| OSVDB ID | Disclosure Date | Title |
|
74369
Description:
Unknown / Incomplete
|
2011-07-27
|
TYPO3 Backend Serialised User Input Arbitrary File Deletion
|
|
74364
Description:
TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the RemoveXSS function does not validate an unspecified attack vector in Internet Explorer 6. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-27
|
TYPO3 Exposed API RemoveXSS Function XSS
|
|
74370
Description:
Unknown / Incomplete
|
2011-07-27
|
TYPO3 Exposed API ExtDirect Endpoint Consumption DoS
|
|
74493
Description:
Plone contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'type_name' parameter upon submission to the 'Members/ipa/createObject' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-27
|
Plone Members/ipa/createObject type_name Parameter XSS
|
|
76148
Description:
Unknown / Incomplete
|
2011-07-27
|
Google Chrome Multiple Extension Unspecified Information Disclosure
|
|
91169
Description:
XFree86 x11perf is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows a local attacker to inject custom code that will be run with the privilege of the program or user executing the program. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source. This can be done by tricking a user into opening a x11perfcomp file from the local file system or a USB drive in some cases. This attack scenario is certainly possible, but rare.
|
2011-07-27
|
XFree86 x11perf x11perfcomp Search Path Subversion Local Privilege Escalation
|
|
74661
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
|
2011-07-26
|
Linux Kernel mount.cifs Password Protected Mounted CIFS Share Hijacking Weakness
|
|
74660
Description:
(Description Provided by CVE) : The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.
|
2011-07-26
|
Linux Kernel NFS Server File Locking Local DoS
|
|
74051
Description:
Virtual Money Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'catid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-07-26
|
Virtual Money Component for Joomla! index.php catid Parameter SQL Injection
|
|
74181
Description:
(Description Provided by CVE) : Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.
|
2011-07-26
|
ClamAV clamd libclamav/matcher-hash.c cli_hm_scan() Function Crafted Message Handling Remote DoS
|
|
74174
Description:
Unknown / Incomplete
|
2011-07-26
|
ManageEngine ServiceDesk Plus Permission Verifiction Weakness Backup File Deletion
|
|
74169
Description:
ManageEngine ServiceDesk Plus contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'siteName' parameter upon submission to the SiteDef.do script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-26
|
ManageEngine ServiceDesk Plus SiteDef.do siteName Parameter XSS
|
|
74170
Description:
ManageEngine ServiceDesk Plus contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'wsName' parameter upon submission to the ManualNodeAddition.do script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-26
|
ManageEngine ServiceDesk Plus ManualNodeAddition.do wsName Parameter XSS
|
|
74171
Description:
ManageEngine ServiceDesk Plus contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'fullName' parameter upon submission to the TechnicianDef.do script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-26
|
ManageEngine ServiceDesk Plus TechnicianDef.do fullName Parameter XSS
|
|
74172
Description:
ManageEngine ServiceDesk Plus contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'groupName' parameter upon submission to the GroupResourcesDef.do script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-26
|
ManageEngine ServiceDesk Plus GroupResourcesDef.do groupName Parameter XSS
|
|
74173
Description:
ManageEngine ServiceDesk Plus contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'agreementNumber' parameter upon submission to the LicenseAgreement.do script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-26
|
ManageEngine ServiceDesk Plus LicenseAgreement.do agreementNumber Parameter XSS
|
|
74071
Description:
Samba contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of Samba daemons, and the addition or removal of shares, printers and user accounts . By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-07-26
|
Samba Web Administration Tool (SWAT) Multiple Function CSRF
|
|
74052
Description:
Microsoft IE contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input passed via EUC-JP encoded characters. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-26
|
Microsoft IE EUC-JP Encoding Unspecified XSS
|
|
74152
Description:
(Description Provided by CVE) : The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request.
|
2011-07-26
|
Linux Kernel Xtensa arch/xtensa/kernel/ptrace.c ptrace_setxregs() Function Pointer Verification Weakness Local Kernel Memory Disclosure
|
|
74072
Description:
Samba contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'user' field upon submission to the 'Change password' page. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-26
|
Samba Web Administration Tool (SWAT) Change Password Page user Field XSS
|
|
74264
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via two unspecified ActiveX controls.
|
2011-07-26
|
Invensys Wonderware Information Server Multiple Unspecified ActiveX Overflows
|
|
74523
Description:
(Description Provided by CVE) : WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-force attack.
|
2011-07-26
|
Novell Data Synchronizer Mobility Pack WebAdmin Weak SSL Cipher Support Brute Force Weakness
|
|
74524
Description:
(Description Provided by CVE) : The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which makes it easier for remote attackers to obtain sensitive information by leveraging an unattended workstation.
|
2011-07-26
|
Novell Data Synchronizer Mobility Pack HTTPS Response Caching Restriction Weakness Information Disclosure
|
|
80269
Description:
Corpse botnet C&C contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'states' and 'countrys' parameters upon submission to the index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-26
|
Corpse C&C index.php Multiple Parameter XSS
|
|
74658
Description:
(Description Provided by CVE) : Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability during scan operations with a long SSID value.
|
2011-07-26
|
Linux Kernel trigger_scan / sched_scan SSID Length Handling Bypass
|
|
74182
Description:
Unknown / Incomplete
|
2011-07-26
|
PHP-Barcode php-barcode.php code Parameter popen() Function Arbitrary Shell Command Execution
|
|
74519
Description:
(Description Provided by CVE) : The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensitive GroupWise information via unspecified vectors.
|
2011-07-26
|
Novell Data Synchronizer Mobility Pack WebAdmin Remote Authentication Bypass GroupWise Information Disclosure
|
|
74520
Description:
(Description Provided by CVE) : Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.
|
2011-07-26
|
Novell Data Synchronizer Mobility Pack WebAdmin Unspecified Session Fixation
|
|
74521
Description:
(Description Provided by CVE) : The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
|
2011-07-26
|
Novell Data Synchronizer Mobility Pack Cleartext Admin LDAP Password Disclosure
|
|
74522
Description:
(Description Provided by CVE) : The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
|
2011-07-26
|
Novell Data Synchronizer Mobility Pack Set-Cookie Header HTTPOnly Flag Weakness Unspecified XSS
|
|
76136
Description:
(Description Provided by CVE) : Arora, possibly 0.11 and other versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.
|
2011-07-26
|
Arora Certificate Text Format CN Field RTF Data Parsing Certificate Spoofing Weakness
|
|
76137
Description:
Unknown / Incomplete
|
2011-07-26
|
Psi Certificate Text Format CN Field RTF Data Parsing Certificate Spoofing Weakness
|
|
76816
Description:
(Description Provided by CVE) : The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle (1) a loop between a dot1x enabled port and an open-authentication dot1x enabled port and (2) a loop between a dot1x enabled port and a non-dot1x port, which allows remote attackers to cause a denial of service (traffic storm) via unspecified vectors that trigger many Spanning Tree Protocol (STP) Bridge Protocol Data Unit (BPDU) frames, aka Bug ID CSCtq36327.
|
2011-07-26
|
Cisco IOS cat6000-dot1x Component dot1x Port Weakness Spanning Tree Protocol (STP) Bridge Protocol Data Unit (BPDU) Frame Saturation Remote DoS
|
|
76817
Description:
(Description Provided by CVE) : The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, which allows remote attackers to cause a denial of service (traffic storm) via unspecified vectors that trigger many unicast EAPoL Protocol Data Units (PDUs), aka Bug ID CSCtq36336.
|
2011-07-26
|
Cisco IOS cat6000-dot1x Component dot1x Infinite Loop unicast EAPoL Protocol Data Units (PDUs) Saturation Remote DoS
|
|
74872
Description:
(Description Provided by CVE) : smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
|
2011-07-25
|
Samba smbfs mount.cifs / umount.cifs RLIMIT_FSIZE Value Handling mtab Local Corruption DoS
|
|
74752
Description:
(Description Provided by CVE) : The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.
|
2011-07-25
|
qemu-kvm -runas Option Local Privilege Escalation
|
|
80717
Description:
Mac OS X contains a flaw related to the LDAP authentication. When connecting to an OpenLDAP server Mac OS X Lion allows the user to enter any credentials, bypassing authentication.
|
2011-07-25
|
Apple Mac OS X Lion Any Credentials LDAP Authentication Bypass
|
|
74031
Description:
Unknown / Incomplete
|
2011-07-25
|
CiscoKits/CertificationKits TFTP Service READ Request Parsing Remote DoS
|
|
74162
Description:
(Description Provided by CVE) : BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors.
|
2011-07-25
|
CA ARCserve D2D homepageServlet Google Web Toolkit (GWT) RPC Request Parsing Admin Credential Disclosure
|
|
74180
Description:
KDE kdeutils Ark contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via .ZIP files. This directory traversal attack would allow the attacker to access and delete arbitrary files.
|
2011-07-25
|
KDE kdeutils Ark Traversal Arbitrary File Deletion
|