This page presents a list of vulnerabilities with the longest "time to patch". This is calculated by looking at the vendor informed date and the vendor solution date. In short, once the vendor became aware of the vulnerability, how long did it take them to patch? This timeframe can be used to gauge the maturity of a vendor's security patch response time. Vendors with exceptionally long patch times should evaluate their procedures while customers should remind the vendors that security is important.
| ID |
Disc Date |
Time to Patch |
Title |
|
34395
|
2007-05-08
|
2280 days |
Microsoft Excel Filter Record Handling Remote Code Execution
|
|
A context-dependent memory corruption flaw exists in Excel. It fails to validate filter records resulting in memory corruption. With a specially crafted file, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
|
62740
|
2010-03-04
|
2225 days |
CA SiteMinder WebWorks Help wwhelp/wwhimpl/common/html/frameset.htm Unspecified Parameter XSS
|
|
Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable ...<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3731" target="_blank">CVE</a>)</span> :
|
|
33567
|
2004-06-17
|
1423 days |
XMB U2U Instant Messenger memcp.php recipient Field XSS
|
|
Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-0519" target="_blank">CVE</a>)</span> :
|
|
66388
|
2010-07-15
|
1416 days |
XMB Admin Password Manipulation CSRF
|
|
|
|
78670
|
2011-12-13
|
1352 days |
Oracle Java SE / Java for Business java:compiler Malformed .java Handling DoS
|
|
|
|
81500
|
2011-08-01
|
1308 days |
OpenSSH gss-serv.c ssh_gssapi_parse_ename Function Field Length Value Parsing Remote DoS
|
|
The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-5000" target="_blank">CVE</a>)</span> :
|
|
68706
|
2010-10-18
|
1245 days |
IBM Informix Dynamic Server portmap.exe librpc.dll Crafted RPC Packet Remote Overflow
|
|
IBM Informix Dynamic Server is prone to an overflow condition. 'librpc.dll' in 'portmap.exe' fails to properly sanitize user-supplied input resulting in an integer overflow. With a specially crafted RPC packet with a crafted parameter size sent to TCP port 36890, a remote attacker can potentially execute arbitrary code.
|
|
32912
|
2007-01-17
|
1222 days |
Oracle Database XMLDB Unspecified XSS
|
|
Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for multiple cross-site scripting (XSS) vulnerabilities.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-0273" target="_blank">CVE</a>)</span> :
|
|
48328
|
2008-07-28
|
1221 days |
Apple iTunes Update Authenticity Verification Weakness
|
|
Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-3434" target="_blank">CVE</a>)</span> :
|
|
61205
|
2009-12-17
|
1173 days |
HP Storage OpenView Data Protector Cell Manager _rm32.rm_getMem() Function Remote Overflow
|
|
Integer overflow in the _ncp32._NtrpTCPReceiveMsg function in rds.exe in the Cell Manager Database Service in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via a large value in the size parameter.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-2281" target="_blank">CVE</a>)</span> :
|
|
61206
|
2009-12-16
|
1163 days |
HP Storage OpenView Data Protector Backup Client Service MSG_PROTOCOL Command Remote Overflow
|
|
Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-2280" target="_blank">CVE</a>)</span> :
|
|
64437
|
2010-05-05
|
1144 days |
HP Mercury LoadRunner Agent magentproc.exe Remote Arbitrary Code Execution
|
|
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1549" target="_blank">CVE</a>)</span> :
|
|
33130
|
2007-02-08
|
1072 days |
HP Network Node Manager (NNM) Remote Console Directory Permission Weakness Privilege Escalation
|
|
HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control permission for the %PROGRAMFILES%\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\ovtrcsvc.exe for the HP Open View Shared Trace Service.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-0819" target="_blank">CVE</a>)</span> :
|
|
71952
|
2011-04-19
|
1012 days |
Oracle Multiple Products Oracle Help help/topics/iastop_cs/iastop_cs_farm_page.html locale Parameter XSS
|
|
Multiple Oracle products contain a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'locale' parameter upon submission to the help/topics/iastop_cs/iastop_cs_farm_page.html page. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
71953
|
2011-04-19
|
1012 days |
Oracle Multiple Products Application Service Level Management /em/console/target/svclvl/slrule targetType Parameter SQL Injection
|
|
Unspecified vulnerability in the Application Service Level Management component in Oracle Database Server 11.1.0.7 and Enterprise Manager Grid Control allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Service Level Agreements.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-0787" target="_blank">CVE</a>)</span> :
|
|
12368
|
2004-12-09
|
1011 days |
UseModWiki wiki.pl XSS
|
|
UseModWiki contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the user-submitted content upon submission to the 'wiki.pl' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
68705
|
2010-10-18
|
984 days |
IBM Informix Dynamic Server oninit.exe Logging Function Remote Overflow
|
|
IBM Informix Dynamic Server is prone to an overflow condition. An unspecified logging function in 'oninit.exe' fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted EXPLAIN directive, a remote attacker can potentially execute arbitrary code.
|
|
40401
|
2007-08-14
|
963 days |
IBM AIX cfgcon swcons -p Argument Symlink Local Privilege Escalation
|
|
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create an arbitrary file, and enable world writability of this file, via a symlink attack involving use of the file's name as the argument. NOTE: this issue is due to an incomplete fix for CVE-2007-5804.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5805" target="_blank">CVE</a>)</span> :
|
|
81267
|
2012-04-17
|
914 days |
Oracle Database Server / Enterprise Manager Database Grid Control /em/console/ecm/config/compareWizard/compareWizFirstConfig fConfigGuid Parameter SQL Injection
|
|
Oracle Database Server and Oracle Enterprise Manager Grid Control contain a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /em/console/ecm/config/compareWizard/compareWizFirstConfig script not properly sanitizing user-supplied input to the 'fConfigGuid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
|
72558
|
2011-02-04
|
905 days |
IBM Lotus Domino IMAP/POP3 mail from Command Non-Printable Character Expansion Remote Code Execution
|
|
Multiple stack-based buffer overflows in the (1) POP3 and (2) IMAP services in IBM Lotus Domino allow remote attackers to execute arbitrary code via non-printable characters in an envelope sender address, aka SPR KLYH87LLVJ.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-0919" target="_blank">CVE</a>)</span> :
|
|
72559
|
2011-02-04
|
905 days |
IBM Lotus Domino NRouter Service Calendar Request Attachment Name Parsing Remote Code Execution
|
|
Stack-based buffer overflow in the NRouter (aka Router) service in IBM Lotus Domino allows remote attackers to execute arbitrary code via long filenames associated with Content-ID and ATTACH:CID headers in attachments in malformed calendar-request e-mail messages, aka SPR KLYH87LKRE.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-0918" target="_blank">CVE</a>)</span> :
|
|
72560
|
2011-02-04
|
905 days |
IBM Lotus Domino iCalendar nrouter.exe Meeting Request Content-Type Header Parsing Remote Code Execution
|
|
|
|
72561
|
2011-02-04
|
905 days |
IBM Lotus Domino SMTP Service Multiple Filename Arguments Remote Code Execution
|
|
|
|
66830
|
2010-08-03
|
895 days |
Citrix Multiple Product ICA Connection Graphics Packet Handling Remote Code Execution
|
|
Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2990" target="_blank">CVE</a>)</span> :
|
|
70838
|
2011-02-07
|
890 days |
Novell eDirectory for Linux NCP FileSetLock Request Handling Remote DoS
|
|
Novell eDirectory for Linux contains a flaw that may allow a remote denial of service. The issue is triggered when an error in the NCP implementation is exploited via a crafted FileSetLock NCP request, and will result in a loss of availability.
|
|
22582
|
2006-01-17
|
877 days |
Oracle Application Server Reports Developer rwservlet customize Variable Arbitrary XML File Portion Disclosure
|
|
Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04. NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-0275" target="_blank">CVE</a>)</span> :
|
|
55806
|
2009-07-13
|
876 days |
Microsoft Office Web Components OWC10.Spreadsheet ActiveX msDataSourceObject() Method Memory Corruption
|
|
A memory corruption flaw exists in Office Web Components. The OWC10.Spreadsheet ActiveX control fails to validate calls to the msDataSourceObject method resulting in memory corruption. With a specially crafted website, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
|
56914
|
2009-08-11
|
866 days |
Microsoft Office Web Components OWC10 ActiveX Loading/Unloading Memory Allocation Arbitrary Code Execution
|
|
The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0562" target="_blank">CVE</a>)</span> :
|
|
27852
|
2006-08-08
|
834 days |
Microsoft IE Uninitialized COM Object Memory Corruption
|
|
Microsoft Internet Explorer contains a flaw that may allow a malicious user to execute code on a user's machine. The issue is triggered when user accesses a malicious web page that contains instructions to instantiate an activeX control. It is possible that the flaw may allow execute code resulting in a loss of integrity.
|
|
72714
|
2011-06-01
|
827 days |
Cisco AnyConnect Secure Mobility Client ActiveX IObjectSafety Headend Server Spoofing Remote Code Execution
|
|
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-2039" target="_blank">CVE</a>)</span> :
|
|
70599
|
2011-01-20
|
814 days |
Iconfidant SSL Server Key Exchange Client Master Key Packet Overflow
|
|
Iconfidant SSL Server is prone to an overflow condition. The key exchange functionality fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted client master key packet whose specific length field sums exceed 0x4000, a remote attacker can potentially execute arbitrary code.
|
|
61965
|
2010-01-19
|
804 days |
RealNetworks Multiple Products Invalid ASMRuleBook Structure Overflow
|
|
Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a file with invalid ASMRuleBook structures that trigger heap memory corruption.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4241" target="_blank">CVE</a>)</span> :
|
|
56435
|
2008-11-18
|
790 days |
WebKit WebCore xml/XMLHttpRequest.cpp Set-Cookie HTTP Response Header Restriction Weakness
|
|
xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-6059" target="_blank">CVE</a>)</span> :
|
|
68707
|
2010-10-18
|
783 days |
IBM Informix Dynamic Server DBINFO Keyword SQL Query Remote Overflow
|
|
IBM Informix Dynamic Server is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With specially crafted lengthy DBINFO keyword arguments in an SQL statement, a remote attacker can potentially execute arbitrary code.
|
|
61966
|
2010-01-19
|
770 days |
RealNetworks Multiple Products Crafted GIF File Chunk Size Overflow
|
|
Heap-based buffer overflow in the CGIFCodec::GetPacketBuffer function in datatype/image/gif/common/gifcodec.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via a GIF file with crafted chunk sizes that trigger improper memory allocation.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4242" target="_blank">CVE</a>)</span> :
|
|
14238
|
2005-02-25
|
757 days |
BadBlue ext.dll mfcisapicommand Parameter Remote Overflow
|
|
A REMOTE overflow exists in BadBlue http Server. The BadBlue http Server fails to validate the mfcisapicommand parameter resulting in a buffer overflow. With a specially crafted request, an attacker can cause the execution of arbitrary code resulting in a loss of integrity.
|
|
65507
|
2010-03-01
|
753 days |
EMC Networker portmap.exe librpc.dll Authentication Functionality Multiple Overflows
|
|
Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2753" target="_blank">CVE</a>)</span> :
|
|
62783
|
2010-03-01
|
753 days |
IBM Informix Dynamic Server portmap.exe librpc.dll Authentication Functionality Multiple Overflows
|
|
Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2753" target="_blank">CVE</a>)</span> :
|
|
68040
|
2010-09-14
|
749 days |
IBM Lotus Domino nnotes.dll MailCheck821Address Function iCalendar Email Address ORGANIZER:mailto Header Remote Overflow
|
|
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-3407" target="_blank">CVE</a>)</span> :
|
|
61967
|
2010-01-21
|
741 days |
RealNetworks Multiple Products Crafted Media File HTTP Chunked Transfer Overflow
|
|
RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allow remote attackers to have an unspecified impact via a crafted media file that uses HTTP chunked transfer coding, related to an "overflow."<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4243" target="_blank">CVE</a>)</span> :
|
|
61972
|
2010-01-19
|
739 days |
RealNetworks Multiple Products CMediumBlockAllocator::Alloc Method Crafted RTSP SET_PARAMETER Handling Overflow
|
|
Buffer overflow in the RTSPProtocol::HandleSetParameterRequest function in client/core/rtspprotocol.cpp in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted RTSP SET_PARAMETER request.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4248" target="_blank">CVE</a>)</span> :
|
|
15537
|
2005-04-18
|
738 days |
PayProCart usrauthstamp.php IP Disclosure
|
|
PayProCart contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker uses a cross-site scripting style attack to include the usrauthstamp.php script, which will disclose arbitrary user's IP addresses resulting in a loss of confidentiality.
|
|
61973
|
2010-01-19
|
712 days |
RealNetworks Multiple Products smlrender.dll SMIL File Handling Overflow
|
|
Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows remote attackers to execute arbitrary code via an SMIL file with crafted string lengths.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4257" target="_blank">CVE</a>)</span> :
|
|
56834
|
2009-08-06
|
692 days |
CA Multiple Products Data Transport Services Library (dtscore.dll) Token Searching Routine Remote Overflow
|
|
Stack-based buffer overflow in a token searching function in the dtscore library in Data Transport Services in CA Software Delivery r11.2 C1, C2, C3, and SP4; Unicenter Software Delivery 4.0 C3; CA Advantage Data Transport 3.0 C1; and CA IT Client Manager r12 allows remote attackers to execute arbitrary code via crafted data.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2026" target="_blank">CVE</a>)</span> :
|
|
59966
|
2009-11-10
|
689 days |
Cisco Linksys WAP4400N Association Request Unspecified Remote DoS
|
|
Multiple buffer overflows in the Marvell wireless driver, as used in Linksys WAP4400N Wi-Fi access point with firmware 1.2.17 on the Marvell 88W8361P-BEM1 chipset, and other products, allow remote 802.11-authenticated users to cause a denial of service (wireless access point crash) and possibly execute arbitrary code via an association request with long (1) rates, (2) extended rates, and unspecified other information elements.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5475" target="_blank">CVE</a>)</span> :
|
|
58865
|
2009-10-13
|
665 days |
Microsoft Multiple Products GDI+ TIFF Image Handling Overflow
|
|
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web ...<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2502" target="_blank">CVE</a>)</span> :
|
|
57241
|
2007-10-04
|
657 days |
vtiger CRM include/utils/ListViewUtils.php Disabled Field Restriction Weakness
|
|
include/utils/ListViewUtils.php in vtiger CRM before 5.1.0 allows remote authenticated users to bypass intended access restrictions and read the (1) visibility, (2) location, and (3) recurrence fields of a calendar via a custom view.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3251" target="_blank">CVE</a>)</span> :
|
|
69845
|
2010-12-10
|
654 days |
RealPlayer Multiple Products RealMedia File MDPR Header Array Index Error Arbitrary Code Execution
|
|
A memory corruption flaw exists in RealPlayer. The program fails to sanitize user-supplied input containing a malformed Media Properties Header (MDPR) resulting in memory corruption. With a specially crafted MDPR in a RealMedia file, a context-dependent attacker can execute arbitrary code.
|
|
37923
|
2007-07-11
|
653 days |
SquirrelMail G/PGP (GPG) Plugin gpg_keyring.php deleteKey Function Arbitrary Command Execution
|
|
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php, (b) import_key_text.php, and (c) keyring_main.php; and (2) the keyserver parameter to the gpg_recv_key function in gpg_key_functions.php, as called by gpg_options.php. NOTE: this issue may overlap CVE-2007-3636.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1924" target="_blank">CVE</a>)</span> :
|
|
37924
|
2007-07-11
|
653 days |
SquirrelMail G/PGP (GPG) Plugin gpg_key_functions.php gpg_recv_key Function Arbitrary Command Execution
|
|
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php, (b) import_key_text.php, and (c) keyring_main.php; and (2) the keyserver parameter to the gpg_recv_key function in gpg_key_functions.php, as called by gpg_options.php. NOTE: this issue may overlap CVE-2007-3636.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1924" target="_blank">CVE</a>)</span> :
|
|
57243
|
2007-10-09
|
652 days |
vtiger CRM Unspecified Attachment / Report / Filter Manipulation
|
|
vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) views, and (5) tickets; insert (6) attachments, (7) reports, (8) filters, (9) views, and (10) tickets; and edit (11) reports, (12) filters, (13) views, and (14) tickets via unspecified vectors.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3258" target="_blank">CVE</a>)</span> :
|
|
47397
|
2008-08-12
|
644 days |
Microsoft Office WPGIMP32.FLT Filter WordPerfect Graphics (WPG) File Handling Arbitrary Code Execution
|
|
WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 does not properly parse the length of a WordPerfect Graphics (WPG) file, which allows remote attackers to execute arbitrary code via a crafted WPG file, aka the "WPG Image File Heap Corruption Vulnerability."<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-3460" target="_blank">CVE</a>)</span> :
|
|
61968
|
2010-01-19
|
617 days |
RealNetworks Multiple Products SIPR Codec Field Handling Overflow
|
|
Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via an SIPR codec field with a small length value that triggers incorrect memory allocation.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4244" target="_blank">CVE</a>)</span> :
|
|
61969
|
2010-01-19
|
616 days |
RealNetworks Multiple Products Compressed GIF File Handling Overflow
|
|
Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4245" target="_blank">CVE</a>)</span> :
|
|
45367
|
2008-05-19
|
615 days |
CA Multiple Product caloggerd Log Daemon Traversal Arbitrary File Manipulation
|
|
Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data to arbitrary files via directory traversal sequences in unspecified input fields, which are used in log messages. NOTE: this can be leveraged for code execution in many installation environments by writing to a startup file or configuration file.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2241" target="_blank">CVE</a>)</span> :
|
|
58866
|
2009-10-13
|
614 days |
Microsoft Multiple Products GDI+ TIFF Image Handling Memory Corruption Arbitrary Code Execution
|
|
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression ...<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2503" target="_blank">CVE</a>)</span> :
|
|
60855
|
2009-12-08
|
610 days |
Microsoft Windows Intel Indeo41 Codec IV41 movi Record Handling Overflow
|
|
Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4309" target="_blank">CVE</a>)</span> :
|
|
56915
|
2009-08-11
|
609 days |
Microsoft Office Web Components OWC10.Spreadsheet ActiveX BorderAround() Method Heap Corruption Arbitrary Code Execution
|
|
A heap based buffer overflow exists in Microsoft Office Web Components. With a specially crafted web page, an attacker can cause code execution resulting in a loss of confidentiality and/or availability.
|
|
77086
|
2008-09-08
|
608 days |
Atlassian Confluence Username XSS
|
|
|
|
69836
|
2010-12-10
|
604 days |
RealPlayer Multiple Products Audio Stream Multi-rate Data Remote Overflow
|
|
RealPlayer is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted multi-rate audio stream, a context-dependent attacker can potentially execute arbitrary code.
|
|
53734
|
2009-04-15
|
602 days |
Oracle Database Workspace Manager LT.ROLLBACKWORKSPACE SQL Injection
|
|
Oracle Database contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to Workspace Manager not properly sanitizing user-supplied input to the LT.ROLLBACKWORKSPACE procedure. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
|
35505
|
2007-04-27
|
597 days |
VMware Workstation Shared Folders Feature Host System Arbitrary File Write
|
|
Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allows users on the guest system to write to arbitrary files on the host system via the "Backdoor I/O Port" interface.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-1744" target="_blank">CVE</a>)</span> :
|
|
70058
|
2010-10-13
|
589 days |
Oracle Fusion Middleware BI Publisher Unspecified Response Splitting
|
|
Oracle Fusion Middleware contains a flaw related to the BI Publisher component. The component suffers from a response splitting vulnerability in the '/xmlpserver' script, with the vulnerable parameter '_xuil'. This may allow a remote attacker to conduct cross-site scripting attacks or to phish user credentials using a fake response from the server.
|
|
60437
|
2009-11-19
|
588 days |
PHP on Windows popen Invalid Mode Handling DoS
|
|
|
|
63316
|
2010-03-26
|
577 days |
Novell NetWare NWFTPD.nlm Multiple FTP Command Handling Overflow
|
|
Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long (1) MKD, (2) RMD, (3) RNFR, or (4) DELE command.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0625" target="_blank">CVE</a>)</span> :
|
|
70056
|
2010-10-13
|
574 days |
Oracle Fusion Middleware BPEL Console BPELCONSOLE/DEFAULT/processLog.jsp processName Parameter XSS
|
|
The BPEL Console component in Oracle Fusion Middleware contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'processName' parameter upon submission to the BPELCONSOLE/DEFAULT/processLog.jsp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
|
74931
|
2011-04-20
|
572 days |
Fail2ban Multiple Temporary File Symlink Arbitrary File Append
|
|
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-5023" target="_blank">CVE</a>)</span> :
|
|
76001
|
2011-09-30
|
570 days |
Adobe Photoshop Elements Brush (ABR) File Handling Overflow
|
|
Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted (1) .grd or (2) .abr file, a related issue to CVE-2010-1296.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-2443" target="_blank">CVE</a>)</span> :
|
|
76002
|
2011-09-30
|
570 days |
Adobe Photoshop Elements Gradient (GRD) File Handling Overflow
|
|
Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted (1) .grd or (2) .abr file, a related issue to CVE-2010-1296.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-2443" target="_blank">CVE</a>)</span> :
|
|
67982
|
2010-09-14
|
567 days |
Microsoft Outlook E-mail Content Parsing Remote Overflow
|
|
Microsoft Outlook contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to an integer underflow error when parsing certain content and can be exploited to cause a heap-based buffer overflow via e.g. a specially crafted e-mail message. It may allow execution of arbitrary code, but requires that Outlook is connected to an Exchange server with Online Mode.
|
|
54159
|
2009-04-28
|
567 days |
Symantec Multiple Products Intel Alert Originator Service (IAO.EXE) MsgSys.exe Process Overflow
|
|
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allow remote attackers to execute ...<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1430" target="_blank">CVE</a>)</span> :
|
|
28932
|
2008-05-09
|
558 days |
Tumbleweed Integrated Messaging Exchange (IME) Default Configuration Password Weakness
|
|
By default, the Tumbleweed IME Server places weak restrictions on the password complexity. User passwords are only required to be 7 characters long and contain a minimum of one number and one alphanumeric character. Any user passwords that meet but do not exceed these criteria would be more susceptible to brute force attacks.
|
|
28933
|
2008-05-09
|
558 days |
Tumbleweed Integrated Messaging Exchange (IME) Cookie Password Weak Encoding
|
|
The TW_AUTHENTICATE_SESSION cookie, for the IME application, contains the base64 value of the username and password. If an unauthenticated user checks the "Remember my password" checkbox on the login page, the authenticated user's username and password will be stored in the TW_AUTHENTICATE_SESSION cookie. This cookie is stored in the authenticated user's browser cache until the "Logout" button is clicked or until the cookie expires. The cookie's expiration time is approximately one month from the day the cookie was originally set. ...
|
|
28722
|
2008-05-09
|
558 days |
Tumbleweed Email Firewall (EMF) Administration Module statusView.do Multiple Parameter XSS
|
|
Tumbleweed EMF administration module contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'sort' and 'lineId' variables upon submission to the /emfadmin/statusView.do action. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
|
28735
|
2008-05-09
|
558 days |
Tumbleweed Email Firewall (EMF) GET Request JSESSIONID Session ID Disclosure
|
|
When connecting to the EMF administrative interface, the system will set a JSESSIONID token for session management. If cookies are disabled or the cookie is deleted at any point, the system will begin transmitting the session token via GET request, potentially exposing the session token via the URL. Since the information is stored in the URL, if a page refers the administrator to a resource on a different machine, this information may show up in the logs on an untrusted ...
|
|
28736
|
2008-05-09
|
558 days |
Tumbleweed Email Firewall (EMF) JSESSIONID Session Fixation
|
|
When an initial connection is made to the Tumbleweed administrative web application, the system sets the JSESSIONID token prior to authentication and does not change subsequent to successful authentication. By establishing a connection to the system in order to obtain a new session identifier, an attacker could use this in a crafted URL to potentially fixate an administrative session.
|
|
28737
|
2008-05-09
|
558 days |
Tumbleweed Email Firewall (EMF) Session Concurrency
|
|
Once a session is established and authentication credentials are supplied, the EMF will allow multiple users to connect using the same session identifier without having to re-authenticate. The EMF does not check to ensure the sessions originate from the same IP address. This session concurrency (aka session piggybacking) will last as long as the authenticated session is maintained. The session is only terminated, for all connections, when the logout function is initiated; regardless of which connection makes the request. When ...
|
|
28759
|
2008-05-09
|
553 days |
Tumbleweed Email Firewall (EMF) /emfadmin/logon.do Malformed password Variable Information Disclosure
|
|
The Tumbleweed Email Firewall (EMF) administrative interface login script (logon.do) fails to properly sanitize input to the 'password' variable. By supplying invalid characters such as "&{(.", "&[[{(" or "&{(]}", an attacker can force a servlet exception that will leak the underlying web server and version. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
|
51342
|
2009-01-14
|
550 days |
Oracle Secure Backup login.php rbtool Parameter Arbitrary Command Execution
|
|
Oracle Secure Backup contains a flaw that may allow an attacker to execute arbitrary commands. The issue is triggered when the exec_qr() function in the login.php script receives malformed data in the '$rbtool' parameter, which is later passed to the popen() function, resulting in arbitrary command execution.
|
|
58844
|
2009-10-13
|
545 days |
Microsoft Windows Media Player ASF Runtime Voice Sample Rate Handling Arbitrary Code Execution
|
|
Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted audio file that uses the Windows Media Speech codec, aka "Windows Media Runtime Voice Sample Rate Vulnerability."<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0555" target="_blank">CVE</a>)</span> :
|
|
71614
|
2011-02-15
|
544 days |
Oracle Java SE / Java for Business Deployment Java Runtime WWW-Authenticate Request Remote NTLM Hash Disclosure
|
|
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Windows, Solaris, and, Linux; 5.0 Update 27 and earlier for Windows; and 1.4.2_29 and earlier for Windows allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-4466" target="_blank">CVE</a>)</span> :
|
|
58869
|
2009-10-13
|
536 days |
Microsoft Office Malformed Object Handling Memory Corruption Arbitrary Code Execution
|
|
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2528" target="_blank">CVE</a>)</span> :
|
|
69856
|
2010-12-10
|
533 days |
RealPlayer Multiple Products pnen3260.dll Module AAC File TIT2 Atom Overflow
|
|
RealPlayer is prone to an overflow condition. The pnen3260.dll module fails to properly parse the TIT2 atom within AAC files resulting in an integer overflow. With a specially crafted TIT2 atom within an AAC file, a context-dependent attacker can potentially execute arbitrary code.
|
|
69834
|
2010-12-10
|
533 days |
RealPlayer Multiple Products ICY SHOUTcast Stream StreamTitle Tag Use-after-free Arbitrary Code Execution
|
|
A memory corruption flaw exists in RealPlayer.An error in the processing of the "StreamTitle" tag in a SHOUTcast stream using the ICY protocol may be exploited to cause memory corruption. With a specially crafted StreamTitle tag in an ICY SHOUTcast stream a context-dependent attacker can execute arbitrary code.
|
|
69837
|
2010-12-10
|
533 days |
RealPlayer Multiple Products RTSP Stream GIF87a File Screen Descriptor Header Remote Overflow
|
|
RealPlayer is prone to an overflow condition. The program fails to properly parse large Screen Width values in the Screen Descriptor headers of GIF87a files, resulting in a heap-based buffer overflow. With a specially crafted GIF87a file, a context-dependent attacker can potentially execute arbitrary code.
|
|
69838
|
2010-12-10
|
533 days |
RealPlayer Multiple Products Real Audio File Cook Codec Multiple Subbands Overflow
|
|
RealPlayer is prone to an overflow condition. The program fails to properly parse large numbers of subbands in cook audio codec information encapsulated in a Real Audio media file, resulting in a heap-based buffer overflow. With a specially crafted Real Audio file, a context-dependent attacker can potentially execute arbitrary code.
|
|
57242
|
2008-02-06
|
532 days |
vtiger CRM Account Billing / Shipping Address Overwrite
|
|
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3257" target="_blank">CVE</a>)</span> :
|
|
62612
|
2010-03-01
|
529 days |
IBM Lotus Domino Web Access ActiveX Unspecified Overflow
|
|
Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, 8.0, 8.0.2, and before 229.281 for Domino 8.0.2 FP4 allows remote attackers to execute arbitrary code via a long URL argument to an unspecified method, aka PRAD7JTNHJ.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0919" target="_blank">CVE</a>)</span> :
|
|
63919
|
2010-04-15
|
528 days |
AgentX++ AgentX::receive_agentx() Function Remote Overflow
|
|
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1318" target="_blank">CVE</a>)</span> :
|
|
63920
|
2010-04-15
|
528 days |
AgentX++ AgentX::receive_agentx() Function Integer Overflow
|
|
Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted payload length.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1319" target="_blank">CVE</a>)</span> :
|
|
76518
|
2011-10-18
|
526 days |
Oracle Database Vault DV_ACCTMGR CIPasswordChange API Password Manipulation
|
|
Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2 allows remote authenticated users to affect integrity and availability via unknown vectors related to Privileged Account.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-3511" target="_blank">CVE</a>)</span> :
|
|
76519
|
2011-10-18
|
526 days |
Oracle Database Vault SYSDBA CIPasswordChange API Password Manipulation
|
|
Unspecified vulnerability in the Database Vault component in Oracle Database Server 11.1.0.7 allows remote authenticated users to affect integrity and availability, related to SYSDBA.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-2322" target="_blank">CVE</a>)</span> :
|
|
53741
|
2009-04-15
|
525 days |
Oracle Application Server Oracle Process Manager and Notification (opmn) Daemon POST URI Handling Remote Format String
|
|
Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a format string vulnerability that allows remote attackers to execute arbitrary code via format string specifiers in an HTTP POST URI, which are not properly handled when logging to opmn/logs/opmn.log.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0993" target="_blank">CVE</a>)</span> :
|
|
69806
|
2010-12-14
|
523 days |
Microsoft Office TIFF Image Converter Endian Conversion Buffer Overflow
|
|
Microsoft Office is prone to an overflow condition. The TIFF Import/Export Graphic Filter, after having encountered a specific error, fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially TIFF image, a context-dependent attacker can potentially execute arbitrary code.
|
|
69807
|
2010-12-14
|
523 days |
Microsoft Office Document Imaging Endian Conversion TIFF Image Handling Memory Corruption
|
|
A memory corruption flaw exists in Microsoft Office. The TIFF Import/Export Graphic Filter fails to sanitize user-supplied input when converting the endianness of certain data resulting in memory corruption. With a specially crafted TIFF image, a context-dependent attacker can execute arbitrary code.
|
|
69874
|
2010-09-30
|
520 days |
Novell eDirectory Server Malformed Index Handling Remote DoS
|
|
Novell eDirectory contains a flaw that may allow a remote denial of service. The issue is triggered when the NCP implementation handles a malformed request. It explicitly trusts a field while translating it to an index. If the index is too large, it will result in a loss of availability.
|
|
22304
|
2006-01-10
|
517 days |
Solaris uustat -S Parameter Local Overflow
|
|
Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.<span style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0780" target="_blank">CVE</a>)</span> :
|
|
56916
|
2009-08-11
|
512 days |
Microsoft Office Web Components HTMLURL Parameter ActiveX Spreadsheet Object Handling Overflow
|
|
Office Web Components is prone to an overflow condition. The ActiveX control fails to properly sanitize user-supplied input via the HTMLURL parameter resulting in a buffer overflow. With a specially crafted website, a context-dependent attacker can potentially cause arbitrary code execution.
|
|
29982
|
2008-05-09
|
509 days |
Tumbleweed Integrated Messaging Exchange (IME) TW_TxnAccDeliveryPageEntry.tpl tsi Variable Malformed Input DoS
|
|
Tumbleweed Integrated Messaging Exchange (IME) Server is prone to an input validation weakness that may allow a remote authenticated user to crash the IME Server as well as the Microsoft IIS server. Such an attack would require an administrator to restart the services as the watchdog IIS process is unable to gracefully restart the server. The /ime facility in Tumbleweed Integrated Messaging Exchange (IME) does not properly handle malformed input. The fprintf function in the TW_TxnAccDeliveryPageEntry.tpl script, as reached by ...
|
|
29983
|
2008-05-09
|
509 days |
Tumbleweed Integrated Messaging Exchange (IME) TW_TxnAccMaillistEditEntryStart.tpl lii Variable Malformed Input DoS
|
|
Tumbleweed Integrated Messaging Exchange (IME) Server is prone to an input validation weakness that may allow a remote authenticated user to crash the IME Server as well as the Microsoft IIS server. Such an attack would require an administrator to restart the services as the watchdog IIS process is unable to gracefully restart the server. The /ime facility in Tumbleweed Integrated Messaging Exchange (IME) does not properly handle malformed input. The fprintf function in the TW_TxnAccMaillistEditEntryStart.tpl script, as reached by ...
|