| OSVDB ID | Disclosure Date | Title |
|
16865
Description:
A remote overflow exists in C'Nedra. The network plugin fails to validate data passed to the READ_TCP_STRING() function resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-05-26
|
C'Nedra game_message_functions.cpp READ_TCP_STRING() Function Remote Overflow
|
|
62025
Description:
Unknown / Incomplete
|
2010-01-30
|
C++ Sockets HTTP Header Handling Remote DoS
|
|
43201
Description:
Unknown / Incomplete
|
2006-03-21
|
C++ Sockets Library Crafted Socket Connection Infinite Loop Remote DoS
|
|
43203
Description:
Unknown / Incomplete
|
2008-01-31
|
C++ Sockets Library HTTP Form Data Parser (HttpdForm) Unspecified Issue
|
|
42105
Description:
(Description Provided by CVE) : HTTPSocket.cpp in the C++ Sockets Library before 2.2.5 allows remote attackers to cause a denial of service (crash) via an HTTP request with a missing protocol version number, which triggers an exception. NOTE: some of these details were obtained from third party information.
|
2007-11-07
|
C++ Sockets Library HTTPSocket.cpp Malformed HTTP Request Remote DoS
|
|
43202
Description:
Unknown / Incomplete
|
2006-03-21
|
C++ Sockets Library Utility::rfc1738_encode Overflow
|
|
35187
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre adddocfile.php root_path Parameter Remote File Inclusion
|
|
35635
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in espaces/communiques/annotations.php in C-Arbre 0.6PR7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-1721.
|
2007-04-22
|
C-Arbre annotations.php root_path Parameter Remote File Inclusion
|
|
35188
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre auth_check.php root_path Parameter Remote File Inclusion
|
|
35189
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre browse_current_category.inc.php root_path Parameter Remote File Inclusion
|
|
35190
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre docfile_details.php root_path Parameter Remote File Inclusion
|
|
35191
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre main.php root_path Parameter Remote File Inclusion
|
|
35192
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre mainarticle.php root_path Parameter Remote File Inclusion
|
|
35193
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre maindocfile.php root_path Parameter Remote File Inclusion
|
|
35194
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre modify.php root_path Parameter Remote File Inclusion
|
|
35198
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre mwiki/LocalSettings.php root_path Parameter Remote File Inclusion
|
|
35195
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre new.php root_path Parameter Remote File Inclusion
|
|
35196
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre resource_details.php root_path Parameter Remote File Inclusion
|
|
35186
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre Richtxt_functions.inc.php root_path Parameter Remote File Inclusion
|
|
35197
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.
|
2007-03-27
|
C-Arbre smallsearch.php root_path Parameter Remote File Inclusion
|
|
37172
Description:
(Description Provided by CVE) : The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.
|
2007-06-08
|
c-ares ares_init:randomize_key Function Random Number Generator (RNG) Weakness
|
|
37171
Description:
(Description Provided by CVE) : c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.
|
2007-06-08
|
c-ares DNS Transaction ID Predictable Seed DNS Spoofing
|
|
57635
Description:
(Description Provided by CVE) : c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
|
2003-05-14
|
c-client IMAP Client literal_size Remote Overflow
|
|
11766
Description:
(Description Provided by CVE) : c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
|
2003-05-14
|
c-client IMAP Client Mailbox Size Overflow
|
|
89304
Description:
c-icap Server contains a flaw in the parse_request() function of request.c that may allow a remote denial of service. The issue is triggered when the buffer fails to contain a ' ' or '?' symbol, which will cause the end pointer to increase and surpass allocated memory. With a specially crafted request (e.g. via the OPTIONS method), a remote attacker can cause a loss of availability for the program.
|
2013-01-15
|
c-icap Server request.c parse_request() Function Remote DoS
|
|
32159
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-News.fr C-News 1.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) formulaire_commentaires.php, (2) affichage/liste_news.php, (3) affichage/news_complete.php, or (4) affichage/pagination.php. NOTE: the provenance of some of this information is unknown; some details are obtained from third party information.
|
2006-12-11
|
C-News affichage/liste_news.php path Parameter Remote File Inclusion
|
|
32160
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-News.fr C-News 1.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) formulaire_commentaires.php, (2) affichage/liste_news.php, (3) affichage/news_complete.php, or (4) affichage/pagination.php. NOTE: the provenance of some of this information is unknown; some details are obtained from third party information.
|
2006-12-11
|
C-News affichage/news_complete.php path Parameter Remote File Inclusion
|
|
32161
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-News.fr C-News 1.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) formulaire_commentaires.php, (2) affichage/liste_news.php, (3) affichage/news_complete.php, or (4) affichage/pagination.php. NOTE: the provenance of some of this information is unknown; some details are obtained from third party information.
|
2006-12-11
|
C-News affichage/pagination.php path Parameter Remote File Inclusion
|
|
28552
Description:
C-News contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to commentaires.php not properly sanitizing user input supplied to the 'path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-05
|
C-News commentaires.php path Parameter Remote File Inclusion
|
|
32158
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in C-News.fr C-News 1.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) formulaire_commentaires.php, (2) affichage/liste_news.php, (3) affichage/news_complete.php, or (4) affichage/pagination.php. NOTE: the provenance of some of this information is unknown; some details are obtained from third party information.
|
2006-12-11
|
C-News formulaire_commentaires.php path Parameter Remote File Inclusion
|