This page presents a list of vulnerabilities with the longest "time of exposure". This is calculated by looking at the exploit publication date and the vendor solution date. During this period, consumers may be vulnerable to the issue while public exploit code exists, allowing for easier and more widespread attacks.
| ID |
Disc Date |
Days of Exposure |
Title |
|
73824
|
2011-07-13
|
657437 days |
TCExam /admin/code/tce_edit_backup.php backup_file Parameter XSS
|
|
TCExam contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'backup_file' parameter upon submission to the /admin/code/tce_edit_backup.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
15631
|
2005-03-31
|
12873 days |
PHP Multiple Unspecified Issues
|
|
PHP contains multiple unspecified vulnerabilities. No further details have been provided. As of July 20, 2010, David Litchfield / NGS has not replied to mails asking for details about the vulnerabilities discovered.
|
|
93240
|
2001-03-25
|
4422 days |
MIT Kerberos 5 kpasswd Service Spoofed Packet Remote DoS
|
|
MIT Kerberos 5 contains a flaw in the kpasswd service that may allow a remote denial of service. The issue is due to the program responding to all requests contacted via the UDP port. With a malformed spoofed packet sent to multiple machines running the vulnerable service, a remote attacker can cause a saturation of data and cause an exhaustion of system resources
|
|
90171
|
2003-09-02
|
3367 days |
GNU C Library (glibc) printf() Incomplete Multibyte Sequence Handling Infinite Loop DoS
|
|
GNU C Library (glibc) contains a flaw in the printf() function that may allow a denial of service. The issue is triggered during the handling of an incomplete multibyte sequence. This may allow a context-dependent attack to cause an infinite loop.
|
|
49736
|
2000-08-15
|
3011 days |
Microsoft Windows SMB NTLM Authentication Credential Replay Remote Code Execution
|
|
Windows contains a flaw that may allow a malicious remote user to execute arbitrary code. The issue is triggered by a flaw that allows an attacker to replay the NTLM credentials of a client user. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
|
88592
|
2005-01-16
|
2872 days |
phpGiftReq index.php Multiple Parameter SQL Injection
|
|
phpGiftReq contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'messagid', 'shopper', and 'shopfor' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
|
88591
|
2005-01-16
|
2872 days |
phpGiftReq item.php itemid Parameter SQL Injection
|
|
phpGiftReq contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the item.php script not properly sanitizing user-supplied input to the 'itemid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
|
54837
|
2001-02-02
|
2593 days |
IBM WebSphere Application Server (WAS) Traversal Error Page XSS
|
|
IBM WebSphere Application Server (WAS) contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because, when returning an error page, the application does not filter script embedded into any area of the server's URL except the rootspace upon submission to the WebContainer script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
88569
|
1995-07-12
|
2424 days |
HP-UX FTP Server (ftpd) Privileged Port Scan Bounce Weakness
|
|
HP-UX FTP Server (ftpd) contains a flaw that may lead to an information disclosure. The problem is that the FTP server does not validate IP addresses supplied via the PORT command while in passive(PASV) mode. It is possible for a remote attacker to establish a connection between the FTP server and an arbitrary port on a third-party system, essentially conducting a port-scan. This can be used to obscure the the source of the port-scan, as well as scan internal systems ...
|
|
59037
|
2002-12-01
|
2016 days |
Thatware auth.inc.php user Parameter SQL Injection
|
|
Thatware contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'auth.inc.php' script not properly sanitizing user-supplied input to the 'user' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
|
829
|
2001-07-02
|
1628 days |
IBM WebSphere Application Server (WAS) Java Servlet Error Page XSS
|
|
IBM WebSphere contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user input upon submission to the Java Servlet which is in turn passed to the error handler. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
|
15123
|
2005-03-30
|
1549 days |
Kerio Personal Firewall Network Rules Process Masquerade Local Bypass
|
|
Kerio Personal Firewall contains a flaw that may allow a malicious user with access to the victim local system the ability to launch malicious programs to bypass the firewalls rules resulting in a loss of confidentiality.
|
|
14987
|
2004-03-26
|
1537 days |
XMB Forum post.php Multiple Parameter XSS
|
|
XMB Forum contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'message' or 'icons' variables upon submission to the post.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
|
33567
|
2004-06-17
|
1423 days |
XMB U2U Instant Messenger memcp.php recipient Field XSS
|
|
Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-0519" target="_blank">CVE</a>)</span> :
|
|
91766
|
2003-08-26
|
1407 days |
dpkg Tar Archive Extraction Incorrect File Permissions Setting Weakness
|
|
dpkg contains a flaw that is due to the program setting permissions based on the program rather than the user during the extraction of .tar archives. This may allow a context-dependent attacker to write files to a system with arbitrary an arbitrary UID.
|
|
5854
|
1996-05-21
|
1302 days |
NetKit inetd SYN/RST Half-open Packet Scan Remote DoS
|
|
Denial of service of inetd on Linux through SYN and RST packets.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=1999-0216" target="_blank">CVE</a>)</span> :
|
|
88201
|
2007-08-10
|
1222 days |
SpringSource Hyperic HQ Sybase Database Plugin Monitor Perl Script Local Password Disclosure
|
|
SpringSource Hyperic HQ contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an error occurs in the Sybase database plugin monitor when a perl script is running. This may allow a local attacker to gain access to password information.
|
|
86509
|
2009-04-22
|
1140 days |
Mozilla Firefox Malformed Quoted src XSS Weakness
|
|
Mozilla Firefox contains a weakness that could help facilitate remote cross-site scripting (XSS) attacks. This flaw exists because the browser parser does not properly validate malformed quoted src attributes (e.g. no closing quote) in HTML. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server, and bypass XSS filtering mechanisms.
|
|
73563
|
2008-02-01
|
1117 days |
Universal Feed Parser (feedparser) feedparser.py DOCTYPE Declaration DoS
|
|
Universal Feed Parser (feedparser) contains a flaw in the handling of DOCTYPE declarations that may allow a denial of service. The issue is due to an error when handling malformed DOCTYPE declarations. With a specially crafted file, a context-dependent attacker can cause the application to crash.
|
|
36802
|
2007-06-04
|
1057 days |
Madirish Webmail lib/addressbook.php GLOBALS[basedir] Parameter Remote File Inclusion
|
|
Madirish Webmail contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'lib/addressbook.php' script not properly sanitizing user input supplied to the 'GLOBALS[basedir]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
|
88572
|
1995-07-13
|
1023 days |
Digital Unix FTP Server (ftpd) Privileged Port Scan Bounce Weakness
|
|
Digital Unix FTP Server (ftpd) contains a flaw that may lead to an information disclosure. The problem is that the FTP server does not validate IP addresses supplied via the PORT command while in passive(PASV) mode. It is possible for a remote attacker to establish a connection between the FTP server and an arbitrary port on a third-party system, essentially conducting a port-scan. This can be used to obscure the the source of the port-scan, as well as scan internal ...
|
|
90797
|
2008-05-27
|
963 days |
Cerberus Helpdesk Arbitrary Group Custom Fields Disclosure
|
|
Cerberus Helpdesk contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to an error in the 'customize' ticket worklist that may allow a remote attacker to gain access to custom fields in arbitrary groups.
|
|
66441
|
2008-04-12
|
950 days |
Siemens SIMATIC WinCC SQL Database Default Password
|
|
By default, Siemens SIMATIC installs with a default password for accessing the SQL database. The 'WinCCConnect' and 'WinCCAdmin' accounts have a password of '2WSXcder' which is publicly known and documented. This allows attackers to trivially access the program or system.
|
|
12368
|
2004-12-09
|
942 days |
UseModWiki wiki.pl XSS
|
|
UseModWiki contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the user-submitted content upon submission to the 'wiki.pl' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
33130
|
2007-02-08
|
922 days |
HP Network Node Manager (NNM) Remote Console Directory Permission Weakness Privilege Escalation
|
|
HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control permission for the %PROGRAMFILES%\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\ovtrcsvc.exe for the HP Open View Shared Trace Service.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-0819" target="_blank">CVE</a>)</span> :
|
|
86511
|
2010-04-21
|
776 days |
Mozilla Firefox HTML5 Parser Malformed script Tag Parsing XSS Weakness
|
|
Mozilla Firefox contains a weakness that helps facilitate remote cross-site scripting (XSS) attacks. This flaw exists because the browser's HTML5 parser does not properly parse malformed script tags. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
24631
|
2006-04-09
|
762 days |
XMB Forum .swf Actionscript Execution
|
|
Cross-site scripting (XSS) vulnerability in XMB Forum 1.9.5 allows remote attackers to inject arbitrary web script or HTML by uploading a Flash (.SWF) video that contains a getURL function call, which causes the video to be rendered without disabling ActionScript.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-1748" target="_blank">CVE</a>)</span> :
|
|
14238
|
2005-02-25
|
758 days |
BadBlue ext.dll mfcisapicommand Parameter Remote Overflow
|
|
A REMOTE overflow exists in BadBlue http Server. The BadBlue http Server fails to validate the mfcisapicommand parameter resulting in a buffer overflow. With a specially crafted request, an attacker can cause the execution of arbitrary code resulting in a loss of integrity.
|
|
9030
|
1997-09-03
|
741 days |
NetKit (biff+comsat) in.comsat Message Flood Remote DoS
|
|
The in.comsatd daemon on many flavors of unix contains a flaw that may allow a local user or LAN connected user to carry out a denial of service. The issue is triggered when a local attacker sends a huge number of username lines very quickly to the open comsat daemon, which will crash the server, resulting in loss of availability.
|
|
47358
|
2008-08-03
|
733 days |
XEROX Phaser 8400 UDP Packet Handling Remote DoS
|
|
The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-3571" target="_blank">CVE</a>)</span> :
|
|
15537
|
2005-04-18
|
727 days |
PayProCart usrauthstamp.php IP Disclosure
|
|
PayProCart contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker uses a cross-site scripting style attack to include the usrauthstamp.php script, which will disclose arbitrary user's IP addresses resulting in a loss of confidentiality.
|
|
90276
|
2010-05-24
|
712 days |
Apache Axis2 axis2.xml Plaintext Password Local Disclosure
|
|
Apache Axis2 contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to the program storing password information in plaintext in the axis2.xml file, which may allow a local attacker to gain access to such information.
|
|
24166
|
2006-03-27
|
622 days |
phpmyfamily track.php name Parameter XSS
|
|
phpmyfamily contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'name' variable upon submission to the 'track.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
|
24167
|
2006-03-27
|
622 days |
phpmyfamily index.php PHPSESSID CRLF Injection Path Disclosure
|
|
Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-1425" target="_blank">CVE</a>)</span> :
|
|
42186
|
2008-02-14
|
582 days |
PHP Live! admin/traffic/knowledge_searchm.php questid Parameter SQL Injection
|
|
PHP Live! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin/traffic/knowledge_searchm.php' script not properly sanitizing user-supplied input to the 'questid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
|
42559
|
2008-02-28
|
473 days |
Podcast Generator loadparser.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'loadparser.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42560
|
2008-02-28
|
473 days |
Podcast Generator admin.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42562
|
2008-02-28
|
473 days |
Podcast Generator categories_add.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'categories_add.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42563
|
2008-02-28
|
473 days |
Podcast Generator categories_remove.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'categories_remove.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42564
|
2008-02-28
|
473 days |
Podcast Generator edit.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'edit.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42565
|
2008-02-28
|
473 days |
Podcast Generator editdel.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'editdel.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42566
|
2008-02-28
|
473 days |
Podcast Generator ftpfeature.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'ftpfeature.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42567
|
2008-02-28
|
473 days |
Podcast Generator login.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'login.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42568
|
2008-02-28
|
473 days |
Podcast Generator pgRSSnews.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'pgRSSnews.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42569
|
2008-02-28
|
473 days |
Podcast Generator showcat.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'showcat.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42570
|
2008-02-28
|
473 days |
Podcast Generator upload.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'upload.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42571
|
2008-02-28
|
473 days |
Podcast Generator archive_cat.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'archive_cat.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42572
|
2008-02-28
|
473 days |
Podcast Generator archive_nocat.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'archive_nocat.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
42573
|
2008-02-28
|
473 days |
Podcast Generator recent_list.php absoluteurl Parameter Remote File Inclusion
|
|
Podcast Generator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'recent_list.php' not properly sanitizing user input supplied to the 'absoluteurl' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
|
25073
|
2006-04-28
|
434 days |
Microsoft IE mhtml: Redirection Domain Restriction Bypass
|
|
Internet Explorer contains a flaw that may allow a malicious user to access documents served from another web site. The issue is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. It is possible that the flaw may allow a malicious website to access properties of a site in an arbitrary external domain in the context of the victim user's browser resulting in a loss of confidentiality.
|
|
73566
|
2009-11-18
|
433 days |
Universal Feed Parser (feedparser) feedparser.py Nested CDATA Stanza XSS
|
|
Universal Feed Parser (feedparser) contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate nested CDATA stanzas upon submission to the feedparser.py script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
91405
|
2012-01-03
|
409 days |
Inkscape /tmp Directory EPS File Loading Weakness
|
|
Inkscape contains a flaw that is due to the program insecurely loading EPS files from the /tmp directory rather than the current directory in use. This may allow an attacker to inject a malicious file in the /tmp directory and have it executed by the program.
|
|
87943
|
2011-04-04
|
407 days |
Facter Search Path Subversion Local Privilege Escalation
|
|
Facter is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows a local attacker to inject custom code that will be run with the privilege of the ...
|
|
75902
|
2011-01-20
|
405 days |
WebCalendar Multiple Script Direct Request Path Disclosure
|
|
WebCalendar contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a direct request to multiple scripts, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
|
32693
|
2007-01-17
|
390 days |
Apple Mac OS X Minimal SLP v2 Service Agent (slpd) Registration Request Overflow
|
|
A buffer overflow exists in Mac OS X. slpd fails to validate the attr-list field of registration requests resulting in a stack overflow. With a specially crafted request, a local attacker can cause arbitrary code execution resulting in a loss of integrity.
|
|
57735
|
1990-04-11
|
371 days |
expreserve /tmp/Ex$PID Race Condition Arbitrary File Ownership Modification
|
|
|
|
41199
|
2007-12-14
|
368 days |
Drake CMS index.php option Parameter XSS
|
|
Input passed to the "option" parameter in "index.php" is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in the context of an affected web site.
|
|
41494
|
2008-02-07
|
365 days |
Adobe Reader / Acrobat EScript.api Plug-in Crafted PDF Arbitrary Code Execution
|
|
Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in. NOTE: this issue might be subsumed by CVE-2008-0655.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5663" target="_blank">CVE</a>)</span> :
|
|
64540
|
2010-03-23
|
359 days |
SAP GUI SAPBExCommonResources.BExGlobal ActiveX Arbitrary Command Execution
|
|
|
|
49325
|
2008-10-13
|
357 days |
Oracle Database Workspace Manager SYS.LT.MERGEWORKSPACE SQL Injection
|
|
Oracle Database contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the SYS.LT package not properly sanitizing user-supplied input to the MERGEWORKSPACE procedure. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
|
81872
|
2012-05-04
|
357 days |
GetSimple CMS admin/upload.php path Parameter XSS
|
|
GetSimple CMS contains a flaw that allows a reflected cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'path' parameter upon submission to the admin/upload.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
14993
|
2005-03-21
|
345 days |
XMB Profile Mood Variables XSS
|
|
Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) "Send To" fields.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2005-0885" target="_blank">CVE</a>)</span> :
|
|
76456
|
2011-06-29
|
342 days |
IBM DB2 Tivoli Monitoring Agent (ITMA) db2rspgn libkbb.so Path Subversion Arbitrary DLL Injection Code Execution
|
|
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-4061" target="_blank">CVE</a>)</span> :
|
|
76457
|
2011-06-29
|
342 days |
IBM DB2 Tivoli Monitoring Agent (ITMA) kbbacf1 libkbb.so Path Subversion Arbitrary DLL Injection Code Execution
|
|
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-4061" target="_blank">CVE</a>)</span> :
|
|
72411
|
2011-05-18
|
321 days |
Room Juice display.php filename Parameter XSS
|
|
Room Juice contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'filename' parameter upon submission to the 'display.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
21488
|
2005-12-01
|
320 days |
Interspire FastFind index.php query Parameter XSS
|
|
Interspire FastFind contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'query' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
30214
|
2006-11-06
|
296 days |
Microsoft Windows GDI Kernel Structure Modification Code Execution
|
|
The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-5758" target="_blank">CVE</a>)</span> :
|
|
53333
|
2009-03-23
|
295 days |
Apple Mac OS X XNU User Space Interaction Restriction Weakness Local Privilege Escalation
|
|
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1235" target="_blank">CVE</a>)</span> :
|
|
60586
|
2009-12-01
|
292 days |
phpMyFAQ index.php Multiple Parameter XSS
|
|
phpMyFAQ versions < 2.5.5 contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the sitemap&lang, search&search, search&tagging_id, artikel&highlight, artikel&artlang, sitemap&letter, show&lang, show&cat, news&newsid=1&newslang, send2friend&artlang, send2friend&cat, send2friend&id, translate&srclang, translate&id, translate&cat, add&cat, add&question parameters upon submission to the index.php?action= script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the ...
|
|
59001
|
2009-03-20
|
290 days |
Apache Axis2 xsd Parameter Traversal Arbitrary File Disclosure
|
|
Axis2 contains a flaw that may allow a remote attacker to access arbitrary files. The issue is due to the services applet not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the xsd parameter. This flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
|
23899
|
2006-03-14
|
289 days |
Microsoft Office Excel BIFF File Processing Malformed BOOLERR Record Arbitrary Code Execution
|
|
A local overflow exists in Excel. The product fails to verify the length of BOOLERR records in the BIFF file format resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbityrary code execution resulting in a loss of integrity.
|
|
35128
|
2007-03-11
|
270 days |
AssetMan download_pdf.php pdf_file Parameter Traversal Arbitrary File Access
|
|
Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the pdf_file parameter.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-1427" target="_blank">CVE</a>)</span> :
|
|
78341
|
2012-01-15
|
264 days |
ATutor Multiple Script PATH_INFO Parameter XSS
|
|
ATutor contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the PATH_INFO parameter (URL) upon submission to the multiple scripts listed in the testing notes section. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
92241
|
2010-10-07
|
259 days |
Apple Mac OS X tnftpd Server Process GLOB_LIMIT Crafted Command Pattern Remote DoS
|
|
Apple Mac OS X contains a flaw in the tnftpd server process that may allow a remote denial of service. The issue is triggered during the handling of a specially crafted command pattern. This may allow a remote attacker to crash the system via the GLOB_LIMIT function.
|
|
15465
|
2005-04-12
|
236 days |
Microsoft IE DHTML Object Memory Corruption Code Execution
|
|
Windows contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when certain DHTML methods are used, leading to a race condition when one thread reads data from memory that has either been overwritten by another thread or has not yet been initialized by another thread. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
|
8101
|
2001-07-02
|
233 days |
UnZip Double Dot Arbitrary File Overwrite
|
|
UnZip contains a flaw that may allow a malicious user to overwrite arbitrary files. The issue is triggered when an archived file contains double dot (..) sequences in the file name, which could allow a malicious user to overwrite arbitrary files on the system resulting in a loss of integrity.
|
|
8102
|
2001-07-02
|
233 days |
UnZip Single Slash Arbitrary File Overwrite
|
|
UnZip contains a flaw that may allow a malicious user to overwrite arbitrary files. The issue is triggered when an archived file contains single slash ('/') sequences in the file name, which could allow a malicious user to overwrite arbitrary files on the system resulting in a loss of integrity.
|
|
82664
|
2012-05-26
|
228 days |
Store Locator Plus Plugin for WordPress /wp-content/plugins/store-locator-le/downloadcsv.php query Parameter SQL Injection
|
|
Store Locator Plus Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /wp-content/plugins/store-locator-le/downloadcsv.php script not properly sanitizing user-supplied input to the 'query' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
|
88795
|
1991-04-01
|
224 days |
SunOS rpc.mountd /etc/exports -access Truncation Remote File System World Mounting Weakness
|
|
SunOS contains a flaw in the rpc.mountd daemon. The issue is triggered during the handling of an /etc/exports file contains an -access string larger than 256 bytes, which will cause the string to become world mounted. Additionally, if an -access string is longer than 1024 bytes the program will truncate it, which will not allow the string to be mounted on the file system or directory.
|
|
72406
|
2011-05-18
|
224 days |
Opera Frameset Construct Handling Memory Corruption
|
|
A memory corruption flaw exists in Opera. The program fails to sanitize user-supplied input when handling frameset constructs during page unloading, resulting in memory corruption. With a specially crafted web page, a context-dependent attacker can execute arbitrary code.
|
|
64918
|
2009-09-25
|
224 days |
html2ps SSI include Directive Traversal Arbitrary File Access
|
|
Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the "include file" SSI directive. NOTE: this issue only might be a vulnerability in limited scenarios, such as if html2ps is invoked by a web application, or if a user-assisted attacker provides filenames whose contents could cause a denial of service, such as certain devices.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-5067" target="_blank">CVE</a>)</span> :
|
|
71190
|
2011-02-23
|
222 days |
Local Market Explorer Plugin for WordPress wp-content/plugins/local-market-explorer/modules/walk-score-iframe.php api-key Parameter XSS
|
|
Local Market Explorer Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'api-key' parameter upon submission to the wp-content/plugins/local-market-explorer/modules/walk-score-iframe.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
72108
|
2011-05-01
|
214 days |
Tine library/vcardphp/vbook.php file Parameter XSS
|
|
Tine contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'file' parameter upon submission to the library/vcardphp/vbook.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
91097
|
2007-09-19
|
212 days |
IBM WebSphere Application Server (WAS) Cached Credential Authentication Policy Bypass
|
|
IBM WebSphere Application Server (WAS) contains a flaw that is due to the authentication process being performing by using a cached entry. This may allow a remote attacker to bypass account lockout policies when LDAP is in use.
|
|
56531
|
2009-01-13
|
211 days |
Premier Election Solutions (Diebold) Global Election Management System (GEMS) Clear Button Audit Log Deletion
|
|
Premier Election Solutions (Diebold) Global Election Management System (GEMS) provides a "Clear" button for the audit log system, which allows operators to delete the audit log without any possibility of restoring it. This violates federal voting system standards requiring indestructible logs to track all system events.
|
|
66388
|
2010-07-15
|
206 days |
XMB Admin Password Manipulation CSRF
|
|
|
|
78132
|
2012-01-03
|
205 days |
OpenEMR validateUser.php u Parameter SQL Injection
|
|
OpenEMR contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'validateUser.php' script not properly sanitizing user-supplied input to the 'u' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
|
92730
|
2009-07-19
|
205 days |
SLiM on Debian Linux /tmp/slim.png Symlink Arbitrary File Overwrite
|
|
SLiM contains a flaw as /tmp/slim.png creates temporary files insecurely. It is possible for a local attacker to use a symlink attack against an unspecified file to cause the program to unexpectedly overwrite an arbitrary file.
|
|
75218
|
2011-09-06
|
196 days |
Blue Coat Reporter Encoded Traversal Arbitary File Access
|
|
Directory traversal vulnerability in Blue Coat Reporter 9.x before 9.2.4.13, 9.2.5.x before 9.2.5.1, and 9.3 before 9.3.1.2 on Windows allows remote attackers to read arbitrary files, and consequently execute arbitrary code, via an unspecified HTTP request.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-5127" target="_blank">CVE</a>)</span> :
|
|
899
|
1997-05-07
|
195 days |
IRIX syserr /usr/tmp/.syserr.data Symlink Arbitrary File Corruption
|
|
SGI syserr program allows local users to corrupt files.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=1999-0327" target="_blank">CVE</a>)</span> :
|
|
83568
|
2001-09-17
|
194 days |
BookMark4U IP-based Access Authentication Bypass
|
|
BookMark4U contains a flaw that may allow an attacker to bypass authentication. The issue is due to the program allowing authentication based on IP address, rather than password. By spoofing an IP address or coming from the same IP as the target (e.g., same ISP, same proxy), an attacker can access the application without providing the password.
|
|
78548
|
2012-01-26
|
193 days |
phpList admin/index.php Multiple Parameter XSS
|
|
phpList contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'testtarget', 'page', 'footer', 'status', 'remote_user', 'remote_database', 'remote_userprefix', 'remote_password', 'remote_prefix' and 'id' parameters upon submission to the admin/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
84588
|
2012-08-06
|
192 days |
HP ArcSight Connector / Logger Appliances File Host Data Handling XSS
|
|
HP ArcSight Connector and Logger Appliances contain a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the applications do not validate certain input when handling file host data before returning it to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
58941
|
2008-12-17
|
183 days |
BIRT birt-viewer/run __report Parameter XSS
|
|
BIRT contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the '__report' parameter upon submission to the birt-viewer/run script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
32769
|
2007-03-01
|
182 days |
PHP Zend Engine Variable Destruction Deep Recursion Overflow
|
|
PHP contains a flaw in the Zend engine that may allow a remote denial of service. The issue is due to the application not enforcing sanity checks for the depth of nested arrays. With a specially crafted request containing deeply nested arrays that triggers deep recursion in the variable destruction routines, a remote attacker can cause a stack exhaustion.
|
|
73474
|
2011-05-12
|
181 days |
GEAR CD DVD Filter Driver GEARAspiWDM.sys Pointers Table Invalid Memory Access Local DoS
|
|
|
|
73475
|
2011-05-12
|
181 days |
GEAR CD DVD Filter Driver GEARAspiWDM.sys Pointers Table Array Indexing Error Invalid Memory Access Local DoS
|
|
|
|
78486
|
2012-01-19
|
181 days |
Rockwell Automation Multiple Product Multiple Parameter Manipulation CIP Message Parsing Remote DoS
|
|
Multiple Rockwell Automation products contain a flaw that may allow a remote denial of service. The issue is triggered during the parsing of a CIP message that changes the devices network and configuration parameters. This will result in a loss of availability for the device and a loss of communication for any device connected to it.
|
|
78487
|
2012-01-20
|
181 days |
Rockwell Automation Multiple Product CIP Packet Parsing Remote Overflow CPU DoS
|
|
Multiple Rockwell Automation products contain an overflow condition that is triggered as user-supplied input is not properly validated when parsing a CIP packet sent for the affected ports. This may allow a remote attacker to cause a buffer overflow, resulting in a denial of service for the CPU. This will cause a loss of availability for the device.
|
|
78488
|
2012-01-20
|
181 days |
Rockwell Automation Multiple Product CIP Packet Parsing Remote Overflow NIC DoS
|
|
Multiple Rockwell Automation products contain an overflow condition that is triggered as user-supplied input is not properly validated when parsing a CIP packet sent for the affected ports. This may allow a remote attacker to cause a buffer overflow, resulting in a denial of service for the network interface card (NIC). This will cause a loss of availability for the device.
|