| OSVDB ID | Disclosure Date | Title |
|
46827
Description:
(Description Provided by CVE) : Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might allow remote attackers to execute arbitrary code via a long lpstrLinkPath argument to the fCreateShellLink function.
|
2008-06-18
|
Microsoft Visual Basic ActiveX (vb6skit.dll) fCreateShellLink Function Crafted lpstrLinkPath Argument Overflow
|
|
46194
Description:
A buffer overflow exists in iPrint Client for Windows. The ienipp.ocx ActiveX control fails to validate data passed to the 'operation,' 'printer-url' and 'target-frame' parameters resulting in a stack overflow. With a specially crafted website, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2008-06-12
|
Novell iPrint Client for Windows ienipp.ocx ActiveX Multiple Variable Overflow
|
|
46105
Description:
CitectSCADA contains an overflow condition in the ODBC Service. The issue is triggered as the size of the second packet received by the service after an initial 4-byte packet is not verified before copying it into a stack buffer. With a specially crafted request, a remote attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2008-06-11
|
CitectSCADA ODBC Service Packet Handling Remote Stack Buffer Overflow
|
|
46073
Description:
(Description Provided by CVE) : Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes within SMIL text in video files, which sends these URIs to explorer.exe and thereby allows remote attackers to execute arbitrary programs, as originally demonstrated by crafted file: URLs.
|
2008-06-10
|
Apple QuickTime Embedded SMIL Text qt:next Attribute Arbitrary File Execution
|
|
46083
Description:
A memory corruption flaw exists in Internet Explorer. IE fails to validate HTML objects resulting in memory corruption. With a specially crafted web page, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2008-06-10
|
Microsoft IE HTML Object Handling Memory Corruption Arbitrary Code Execution
|
|
46263
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
|
2008-06-09
|
IBM DB2 Universal Database XQuery Statement Overflow
|
|
46267
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
|
2008-06-09
|
IBM DB2 Universal Database SQLRLAKA() Overflow
|
|
46264
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
|
2008-06-09
|
IBM DB2 Universal Database XMLQUERY Statement Overflow
|
|
46265
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
|
2008-06-09
|
IBM DB2 Universal Database XMLEXISTS Statement Overflow
|
|
46266
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
|
2008-06-09
|
IBM DB2 Universal Database XMLTABLE Statement Overflow
|
|
46041
Description:
A buffer overflow exists in GroupWise Messenger. The client fails to validate HTTP responses resulting in a stack overflow. With a specially crafted response, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2008-06-05
|
Novell GroupWise Messenger Client (GWIM) NM_A_SZ_TRANSACTION_ID String Server Response Overflow
|
|
46239
Description:
(Description Provided by CVE) : The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.
|
2008-06-04
|
HP Instant Support ActiveX (HPISDataManager.dll) StartApp() Method Arbitrary File Execution
|
|
46012
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.
|
2008-06-04
|
CA Secure Content Manager HTTP Gateway Service (icihttp.exe) PASV Command Overflow
|
|
46013
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.
|
2008-06-04
|
CA Secure Content Manager HTTP Gateway Service (icihttp.exe) LIST Command Response Handling Overflow
|
|
45924
Description:
A buffer overflow exists in HP StorageWorks Storage Mirroring. HP StorageWorks Storage Mirroring fails to verify the length of user-supplied login information resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2008-06-04
|
HP StorageWorks Storage Mirroring (SWSM) Software doubletake.exe Authentication Request Overflow
|
|
45854
Description:
(Description Provided by CVE) : Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers to execute arbitrary code via a long username parameter.
|
2008-06-01
|
Alt-N SecurityGateway.dll Administration Interface username Field Remote Overflow
|
|
45657
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.
|
2008-05-28
|
Samba lib/util_sock.c receive_smb_raw() Function Crafted Packet Handling Overflow
|
|
45724
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow remote attackers to execute arbitrary code via unspecified vectors.
|
2008-05-27
|
NCTSoft Products NCTAudioInformation2 ActiveX (NCTAudioInformation2.dll) Multiple Unspecified Overflows
|
|
45658
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioGrabber2 ActiveX control in NCTAudioGrabber2.dll allow remote attackers to execute arbitrary code via unspecified vectors.
|
2008-05-27
|
Multiple Products NCTSoft NCTAudioGrabber2 ActiveX (NCTAudioGrabber2.dll) Unspecified Overflow
|
|
45610
Description:
A remote overflow exists in Lotus Domino Sametime Server. The Multiplexer StMux.exe in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, fails to restrict string lengths in a POST request resulting in a stack based buffer overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of confidentiality, integrity, and/or availability.
|
2008-05-21
|
IBM Lotus Sametime Community Services Multiplexer (StMux.exe) Remote Overflow
|
|
45422
Description:
(Description Provided by CVE) : Integer overflow in Borland Interbase 2007 SP2 (8.1.0.256) allows remote attackers to execute arbitrary code via a malformed packet to TCP port 3050, which triggers a stack-based buffer overflow. NOTE: this issue might be related to CVE-2008-0467.
|
2008-05-20
|
Borland InterBase Packet Processing Remote Overflow
|
|
45415
Description:
A remote overflow exists in IBM Lotus Domino server. The Web Server component fails to check string lengths in the Accept-Language header resulting in a stack overflow. With a specially crafted request, an attacker can execute code remotely resulting in a loss of integrity.
|
2008-05-20
|
IBM Lotus Domino Web Server Accept-Language HTTP Header Remote Overflow
|
|
45374
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in the PhotoStockPlus Uploader Tool ActiveX control (PSPUploader.ocx) allow remote attackers to execute arbitrary code via unspecified initialization parameters.
|
2008-05-19
|
PhotoStockPlus Uploader Tool ActiveX (PSPUploader.ocx) Multiple Unspecified Overflows
|
|
45368
Description:
(Description Provided by CVE) : Multiple buffer overflows in xdr functions in the server in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allow remote attackers to execute arbitrary code, as demonstrated by a stack-based buffer overflow via a long parameter to the xdr_rwsstring function.
|
2008-05-19
|
CA Multiple Product xdr_rwsstring() Library Function Remote Overflow
|
|
44904
Description:
(Description Provided by CVE) : Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet. NOTE: some of these details are obtained from third party information.
|
2008-05-07
|
TFTP Server SP Error Packet Handling Remote Overflow
|
|
44852
Description:
(Description Provided by CVE) : The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption.
|
2008-05-06
|
Yahoo! Assistant ActiveX (yNotifier.dll) Ynotifier COM Object Arbitrary Code Execution
|
|
44662
Description:
(Description Provided by CVE) : Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.
|
2008-04-24
|
HP HPeDiag HPeSupportDiags.HPIniFileUtil.1 ActiveX (HPeDiag.dll) GetXmlFromIni Method Overflow
|
|
44663
Description:
(Description Provided by CVE) : Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.
|
2008-04-24
|
HP HPeDiag HPeSupportDiags.HPRegUtil.1 ActiveX (HPeDiag.dll) Registry Key Disclosure
|
|
44664
Description:
(Description Provided by CVE) : Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.
|
2008-04-24
|
HP HPeDiag HPeSupportDiags.HPFileUtil.1 ActiveX (HPeDiag.dll) Arbitrary Text File Access
|
|
44665
Description:
(Description Provided by CVE) : Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.
|
2008-04-24
|
HP HPeDiag HPeSupportDiags.HPSystemBoardInfo.1 ActiveX (HPeDiag.dll) System Information Disclosure
|
|
44666
Description:
(Description Provided by CVE) : Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.
|
2008-04-24
|
HP HPeDiag HPeSupportDiags.HPOperatingSystem.1 ActiveX (HPeDiag.dll) Operating System Information Disclosure
|
|
44767
Description:
(Description Provided by CVE) : Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.
|
2008-04-24
|
HP Software Update eSupportDiagnostics ActiveX (hpediag.dll) Unspecified Arbitrary Code Execution
|
|
44868
Description:
(Description Provided by CVE) : Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.
|
2008-04-24
|
IBM Lotus Expeditor Client for Desktop rcplauncher cai URI Handler Arbitrary Remote Code Execution
|
|
44579
Description:
(Description Provided by CVE) : Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244.
|
2008-04-21
|
Adobe Multiple Products Crafted BMP File Handling Overflow
|
|
44649
Description:
(Description Provided by CVE) : The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s800i before 1.1.0.3, when configured to allow unauthenticated calls, does not verify that an ACK response contains a call number matching the server's reply to a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed ACK response that does not complete a 3-way handshake. NOTE: this issue exists because of an incomplete fix for CVE-2008-1923.
|
2008-04-18
|
Asterisk Open Source IAX2 Channel Driver (chan_iax2) Spoofed ACK Response Handshake Remote DoS
|
|
44562
Description:
(Description Provided by CVE) : The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large integer value used in an increment to TCP port 41523, which triggers a buffer over-read.
|
2008-04-17
|
CA BrightStor ARCserve Backup Discovery Service Crafted TCP Packet Handling Remote DoS
|
|
44423
Description:
(Description Provided by CVE) : The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop and Server Management r11.1 through r11.2 C2 allows remote attackers to execute arbitrary code via crafted function arguments.
|
2008-04-16
|
CA Multiple Products DSM gui_cm_ctrls ActiveX (gui_cm_ctrls.ocx) Crafted Function Arguments Arbitrary Code Execution
|
|
44455
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers to execute arbitrary code via a malformed opcode 0x52 request to TCP port 3050. NOTE: this might overlap CVE-2007-5243 or CVE-2007-5244.
|
2008-04-11
|
Borland InterBase Database Service (ibserver.exe) Crafted Opcode Request Remote Overflow
|
|
44654
Description:
(Description Provided by CVE) : ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, 7.53, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain requests that specify a large number of sub-arguments, which triggers a NULL pointer dereference due to memory allocation failure.
|
2008-04-11
|
HP OpenView Network Node Manager (OV NNM) ovalarmsrv Request Handling NULL Dereference Remote DoS
|
|
44282
Description:
(Description Provided by CVE) : Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.
|
2008-04-09
|
Adobe Flash Player Unspecified Input Validation Arbitrary Code Execution
|