| OSVDB ID | Disclosure Date | Title |
|
19309
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Sun Java System Web Proxy Server 3.6 SP7 and earlier allow remote attackers to cause a denial of service (unresponsive service) via unknown vectors.
|
2005-09-09
|
Sun Java System Web Proxy Server Unspecified DoS (6291212)
|
|
19620
Description:
OpenTTD contains a flaw that may allow a malicious user to issue format commands to the network.c program. It is possible that the flaw may terminate the application (DoS) or execute commands, resulting in a loss of confidentiality, or availability.
|
2005-09-06
|
OpenTTD network.c Format String
|
|
19621
Description:
OpenTTD contains a flaw that may allow a malicious user to issue format commands to the network_server.c program. It is possible that the flaw may terminate the application (DoS) or execute commands, resulting in a loss of confidentiality, or availability.
|
2005-09-06
|
OpenTTD network_server.c Format String
|
|
19622
Description:
OpenTTD contains a flaw that may allow a malicious user to issue format commands to the network_client.c program. It is possible that the flaw may terminate the application (DoS) or execute commands, resulting in a loss of confidentiality, or availability.
|
2005-09-06
|
OpenTTD network_client.c Format String
|
|
19623
Description:
OpenTTD contains a flaw that may allow a malicious user to issue format commands to the console_cmds.c program. It is possible that the flaw may terminate the application (DoS) or execute commands, resulting in a loss of confidentiality, or availability.
|
2005-09-06
|
OpenTTD console_cmds.c Format String
|
|
19624
Description:
A remote overflow exists in texteff.c. The OpenTTD file fails to filter input sent to the texteff.c program resulting in a an overflow. With a specially crafted request, an attacker can cause a DoS resulting in a loss of availability.
|
2005-09-06
|
OpenTTD texteff.c Remote Overflow
|
|
19144
Description:
gBook contains a flaw that allows a remote cross site scripting attack. No further details have been provided.
|
2005-09-01
|
gBook HTTP User-Agent Header XSS
|
|
17239
Description:
A remote overflow exists in Novell NetMail. The Novell NetMail IMAP daemon fails to calculate size before allocating memory for the command continuation requests resulting in a heap overflow. With a specially crafted request, an attacker can cause arbitrary code execution with the privileges of the underlying user (usually NetMailService), resulting in a loss of integrity.
|
2005-09-01
|
Novell NetMail IMAP Command Continuation Function Overflow
|
|
19119
Description:
A remote overflow exists in DameWare Mini Remote Control. The 'dwrcs.exe' service fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request containing an overly long username, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-08-31
|
DameWare Mini Remote Control username Remote Overflow
|
|
19287
Description:
Microsoft Windows Firewall contains a flaw that may allow a malicious local user, with administrative privileges, to hide firewall ruleset information. The issue is triggered by a specially crafted Windows Firewall exception entry in the Windows Registry. It is possible that the flaw may not allow firewall exception entries to be displayed in the Windows firewall graphical user interface, resulting in a loss of integrity. The command line firewall administration tool "Netsh" is not affected by this issue
|
2005-08-31
|
Microsoft Windows Firewall Malformed Registry Entry Ruleset Exception Weakness
|
|
29350
Description:
(Description Provided by CVE) : Unspecified vulnerability in the stats module in Gallery 1.5.1-RC2 and earlier allows remote attackers to obtain sensitive information via unspecified attack vectors, related to "two file exposure bugs."
|
2005-08-27
|
The Gallery Stats Module Unspecified File Disclosure
|
|
18956
Description:
Microsoft Windows contains a flaw that may allow a malicious user to to hide specific registry information. The issue is triggered by a vulnerability in the Registry Editor Utility (regedt32.exe) when handling long string names. It is possible that the flaw may allow a local attacker to create a string containing a long name (i.e., under the "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" key) to cause the string and any other strings in the key to become hidden, resulting in a loss of integrity.
|
2005-08-24
|
Microsoft Windows Registry Editor (Regedt32.exe) Long String Obfuscation
|
|
18954
Description:
WebCalendar contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to send_reminders.php not properly sanitizing user input supplied to the 'includedir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-08-24
|
WebCalendar send_reminders.php includedir Parameter Remote File Inclusion
|
|
18926
Description:
Microsoft IIS contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a URL is supplied spoofing the server name in the http GET request. Server scripts that allow elevated privileges when accessed locally may be fooled into thinking a remote request is from a local user. This flaw may lead to a loss of confidentiality or integrity.
|
2005-08-17
|
Microsoft IIS SERVER_NAME Variable Spoofing Filter Bypass
|
|
18695
Description:
Veritas Backup Exec for Windows Servers contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote user sends a CONNECT_CLIENT_AUTH request with a hardcoded password value to trigger the flaw. If successful, the flaw will disclose arbitrary files that are accessible via the Windows system account, resulting in a loss of confidentiality.
|
2005-08-12
|
VERITAS Backup Exec Remote Agent Static Password Arbitrary File Download
|
|
25368
Description:
WebSphere Application Server contains a flaw that may lead to unauthorized access. The issue is triggered when a context is secured using a '/*' directive. Direct access to a context's index page using its file name is covered by an authentication process, whereas a request to the directory itself is not covered. This will disclose the index page without authenticatoin, resulting in a loss of confidentiality.
|
2005-08-11
|
IBM WebSphere Application Server (WAS) Welcome Page Security Bypass
|
|
18763
Description:
ezUpload contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php not properly sanitizing user input supplied to the path variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-08-11
|
ezUpload index.php path Parameter Remote File Inclusion
|
|
18764
Description:
ezUpload contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to initialize.php not properly sanitizing user input supplied to the path variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-08-11
|
ezUpload initialize.php path Parameter Remote File Inclusion
|
|
18765
Description:
ezUpload contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to customize.php not properly sanitizing user input supplied to the path variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-08-11
|
ezUpload customize.php path Parameter Remote File Inclusion
|
|
18766
Description:
ezUpload contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to form.php not properly sanitizing user input supplied to the path variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-08-11
|
ezUpload form.php path Parameter Remote File Inclusion
|
|
18703
Description:
A remote overflow exists in Novell eDirectory iMonitor on Windows. iMonitor fails to handle malformed HTTP GET requests resulting in a stack overflow. With a specially crafted request, an attacker can execute arbitrary code with SYSTEM privileges resulting in a loss of integrity.
|
2005-08-11
|
Novell eDirectory iMonitor on Windows dhost.exe Unspecified Remote Overflow
|
|
18650
Description:
(Description Provided by CVE) : Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows remote attackers to delete arbitrary files via ".." sequences in an "Unlink data file" command.
|
2005-08-09
|
Solaris printd Arbitrary File Deletion
|
|
18896
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.
|
2005-08-08
|
MySQL User-Defined Function init_syms() Function Overflow
|
|
18400
Description:
MySQL Eventum contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'id' variable upon submission to the 'view.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-31
|
MySQL Eventum view.php id Parameter XSS
|
|
18401
Description:
MySQL Eventum contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'release' variable upon submission to the 'list.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-31
|
MySQL Eventum list.php release Parameter XSS
|
|
18402
Description:
MySQL Eventum contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'F' variable upon submission to the 'get_jsrs_data.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-31
|
MySQL Eventum get_jsrs_data.php F Parameter XSS
|
|
18403
Description:
MySQL Eventum contains a flaw that may allow a remote attacker to carry out an SQL injection attack and bypass authentication settings. The issue is due to the 'login.php' script not properly sanitizing user-supplied input to the 'email' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database to bypass authentication.
|
2005-07-31
|
MySQL Eventum login.php email Parameter SQL Injection Authentication Bypass
|
|
18404
Description:
MySQL Eventum contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'custom_fields.php' script not properly sanitizing user-supplied input to the report class. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-31
|
MySQL Eventum custom_fields.php SQL Injection
|
|
18405
Description:
MySQL Eventum contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'custom_fields_graph.php' script not properly sanitizing user-supplied input to the report class. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-31
|
MySQL Eventum custom_fields_graph.php SQL Injection
|
|
18406
Description:
MySQL Eventum contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'releases.php' script not properly sanitizing user-supplied input to the release class. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-31
|
MySQL Eventum releases.php SQL Injection
|
|
18475
Description:
OpenBook contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'admin.php' script not properly sanitizing user-supplied input to the 'User ID' and 'Password' fields. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-30
|
OpenBook admin.php Multiple Field SQL Injection
|
|
18296
Description:
VBZooM contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'show.php' script not properly sanitizing user-supplied input to the 'SubjectID' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-26
|
VBZooM show.php SubjectID Parameter SQL Injection
|
|
18269
Description:
(Description Provided by CVE) : Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as shipped with the Japanese locale, allows local users to gain privileges via unknown attack vectors.
|
2005-07-25
|
Solaris Multi-language Environment Library (libmle) Local Privilege Escalation
|
|
18062
Description:
SEO-Board contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'doc' parameter upon submission to the 'smilies_popup.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2005-07-18
|
SEO-Board smilies_popup.php doc Parameter XSS
|
|
17897
Description:
A remote overflow exists in Winamp. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted mp3 file containing an overly long ID3v2 tag, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-07-14
|
Winamp MP3 ID3v2 Tag Handling Overflow
|
|
17830
Description:
A remote overflow exists in Microsoft Windows. The Microsoft Color Management Module fails to handle International Color Consortium (ICC) profile format tag validation before passing it to the buffer, resulting in a buffer overflow. With a specially crafted malicious image file, an attacker can execute arbitrary code with privileges of the victim, resulting in a loss of integrity.
|
2005-07-12
|
Microsoft Windows Color Management Module ICC Profile Format Tag Remote Overflow
|
|
17813
Description:
(Description Provided by CVE) : The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.
|
2005-07-11
|
dhcpcd Unspecified Out-of-bounds Memory Access DoS
|
|
17821
Description:
Novell NetMail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application automatically processes HTML in an attachment without prompting the user to save or open it. This could allow a user to create a specially crafted html e-mail attachment that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-08
|
Novell NetMail HTML File Attachment Arbitrary Script Insertion
|
|
17810
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and possibly other vectors.
|
2005-07-08
|
CA eTrust SiteMinder login.fcc Arbitrary iframe Injection
|
|
17827
Description:
(Description Provided by CVE) : zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.
|
2005-07-07
|
zlib inftrees.c Crafted Compressed Stream Overflow DoS
|