| OSVDB ID | Disclosure Date | Title |
|
45110
Description:
Unknown / Incomplete
|
1997-11-01
|
3-Way Algorithm Related-key Cryptanalysis Weakness
|
|
25203
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this issue might be resultant from the directory traversal vulnerability.
|
2006-05-02
|
321soft Php-Gallery index.php path Parameter XSS
|
|
25202
Description:
(Description Provided by CVE) : Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter.
|
2006-05-02
|
321soft Php-Gallery index.php path Variable Arbitrary Directory Listing
|
|
68703
Description:
32bit FTP Client is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted overly long LIST response, a context-dependent attacker can potentially execute arbitrary code.
|
2010-10-12
|
32bit FTP Client LIST Command Response Filename Handling Overflow
|
|
54416
Description:
(Description Provided by CVE) : Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD command.
|
2009-05-05
|
32bit FTP CWD Command 257 Reply Handling Overflow
|
|
66808
Description:
Unknown / Incomplete
|
2010-08-02
|
32bit FTP Directory Download Traversal Arbitrary File Creation
|
|
54584
Description:
(Description Provided by CVE) : Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 227 reply to a PASV command.
|
2009-05-05
|
32bit FTP PASV Command 227 Reply Handling Overflow
|
|
60158
Description:
(Description Provided by CVE) : Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.
|
2003-02-04
|
32bit FTP Server Banner Overflow DoS
|
|
54219
Description:
(Description Provided by CVE) : Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long banner. NOTE: this might overlap CVE-2003-1368.
|
2009-05-05
|
32bit FTP Server Banner Response Handling Remote Overflow
|
|
26507
Description:
35mm Slide Gallery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the imgdir variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-13
|
35mm Slide Gallery index.php imgdir Parameter XSS
|
|
26508
Description:
35mm Slide Gallery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the w, h and t variables upon submission to the popup.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-13
|
35mm Slide Gallery popup.php Multiple Parameter XSS
|
|
64349
Description:
Unknown / Incomplete
|
2010-05-05
|
360 Anti-Virus / Security Guard 360FkAdv.sys IOCTL Handling Local DoS
|
|
64348
Description:
Unknown / Incomplete
|
2010-05-05
|
360 Anti-Virus / Security Guard profos.sys IOCTL Handling Local DoS
|
|
78591
Description:
360 KouXin Application for Android contains a flaw related that may allow a remote attacker to access and manipulate data relating to a user's SMS or contact list.
|
2011-12-14
|
360 KouXin (com.qihoo360.kouxin) Application for Android Unspecified User SMS / Contact List Manipulation
|
|
78587
Description:
360 MobileSafe Application for Android contains a flaw related that may allow a remote attacker to access and manipulate data relating to SMS and the contact list.
|
2011-12-13
|
360 MobileSafe (com.qihoo360.mobilesafe) Application for Android Unspecified User SMS / Contact List Manipulation
|
|
64350
Description:
Unknown / Incomplete
|
2010-05-05
|
360 Safe SafeBoxKrnl.sys IOCTL Handling Arbitrary Process Termination
|
|
64351
Description:
Unknown / Incomplete
|
2010-05-05
|
360 Safe SafeBoxKrnl.sys IoFreeMdl() Function Memory Corruption Code Execution
|
|
62072
Description:
Unknown / Incomplete
|
2010-02-01
|
360 Security Guard bregdrv.sys BRegSetValueEx() Function Local Privilege Escalation
|
|
89360
Description:
By default, 360 Systems Image Server 2000 installs with default user credentials (username/password combination). The 'ADMINISTRATOR' account has a password of '3ware', which is publicly known and documented. This allows remote attackers to trivially access the program or system and gain privileged access.
|
2008-04-25
|
360 Systems Image Server 2000 Hardcoded Default Credentails
|
|
65354
Description:
Unknown / Incomplete
|
2010-05-25
|
360 Web Manager /menu/sub-menu-led-01.php IDM Parameter XSS
|
|
72110
Description:
Unknown / Incomplete
|
2011-04-15
|
360 Web Manager adm/barra/assetmanager/assetmanager.php Arbitrary File Upload
|
|
72109
Description:
360 Web Manager contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker accesses the HTML source code of the adm/barra/assetmanager/assetmanager.php script, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2011-04-15
|
360 Web Manager adm/barra/assetmanager/assetmanager.php HTML Source Installation Path Disclosure
|
|
72111
Description:
360 Web Manager contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the adm/barra/assetmanager/assetmanager.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via an unspecified parameter. This directory traversal attack would allow the attacker to list or delete arbitrary files.
|
2011-04-15
|
360 Web Manager adm/barra/assetmanager/assetmanager.php Unspecified Parameter Traversal Arbitrary File Manipulation
|
|
40955
Description:
(Description Provided by CVE) : SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter.
|
2008-01-20
|
360 Web Manager form.php IDFM Parameter SQL Injection
|
|
65355
Description:
360 Web Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the webpages-form-led-edit.php script not properly sanitizing user-supplied input to the 'IDFM' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-25
|
360 Web Manager webpages-form-led-edit.php IDFM Parameter SQL Injection
|
|
81508
Description:
360zip contains a flaw related to file browsing and extraction that may allow a remote attacker to execute arbitrary code. No further details have been provided.
|
2012-01-01
|
360zip File Browsing / Extraction Remote Code Execution
|
|
91252
Description:
389 Directory Server contains a flaw in the get_ldapmessage_controls_ext() function that may allow a remote denial of service. The issue is triggered when handling LDAP control data. With a specially crafted LDAP control sequence with a zero length, a remote attacker can crash the server.
|
2013-02-02
|
389 Directory Server get_ldapmessage_controls_ext() Function Zero Length LDAP Control Sequence Handling Remote DoS
|
|
83233
Description:
389 Directory Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by LDAP during password change operations, which will disclose unhashed password information to an attacker with access to network traffic between the LDAP server and the user.
|
2012-06-22
|
389 Directory Server LDAP Password Change Remote Unhashed Password Disclosure
|
|
93360
Description:
389 Directory Server contains a flaw in the do_search function in ldap/servers/slapd/search.c that may lead to the unauthorized disclosure of sensitive information. The issue is triggered when handling a specially crafted LDAP search. This may allow a remote attacker to gain access to potentially sensitive information.
|
2013-03-28
|
389 Directory Server ldap/servers/slapd/search.c do_search Function Crafted LDAP Search Handling Information Disclosure
|
|
85772
Description:
389 Directory Server contains a flaw that is triggered during the handling of a modifyRDN operation. This may allow a remote attacker to bypass the access control list when a DN entry is moved via the database modify RDN function.
|
2012-09-26
|
389 Directory Server modifyRDN Operation Handling ACL Bypass
|