| OSVDB ID | Disclosure Date | Title |
|
35520
Description:
Glossword contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'custom_vars.php' script not properly sanitizing user input supplied to the 'sys[path_addon]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-05-16
|
Glossword custom_vars.php sys[path_addon] Parameter Remote File Inclusion
|
|
37347
Description:
Unknown / Incomplete
|
2007-05-31
|
Glossword Multiple Unspecified Issues
|
|
43599
Description:
Unknown / Incomplete
|
2007-03-09
|
GlowWorm Kernel Extension bignum_cmp() Function Unspecified Null Dereference DoS
|
|
43597
Description:
(Description Provided by CVE) : GlowWorm FW before 1.5.3b4 allows remote attackers to cause a denial of service (kernel panic) via certain DNS responses that trigger infinite recursion in TrueDNS packet parsing, as originally observed with certain login.yahoo.com responses.
|
2007-03-09
|
GlowWorm TrueDNS Packet Handling Infinite Recursion Remote DoS
|
|
43598
Description:
Unknown / Incomplete
|
2007-03-09
|
GlowWorm udp4 Data Handling Unspecified DoS
|
|
36719
Description:
Unknown / Incomplete
|
2007-06-18
|
GLPI (Gestion Libre de Parc Informatique) phpmailer Library Unspecified Issue
|
|
74151
Description:
(Description Provided by CVE) : The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
|
2011-07-20
|
GLPI Autocomplete Remote Credentials Disclosure
|
|
51596
Description:
Unknown / Incomplete
|
2009-01-24
|
GLPI Unspecified SQL Injection
|
|
63124
Description:
Unknown / Incomplete
|
2010-02-18
|
GLPI Unspecified XSS
|
|
67079
Description:
(Description Provided by CVE) : Multiple integer overflows in glpng.c in glpng 1.45 allow context-dependent attackers to execute arbitrary code via a crafted PNG image, related to (1) the pngLoadRawF function and (2) the pngLoadF function, leading to heap-based buffer overflows.
|
2010-08-11
|
glpng glpng.c Multiple Function PNG File Handling Overflow
|
|
46180
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.
|
2008-06-13
|
Glub Tech Secure FTP Crafted Filename Traversal Sequence Arbitrary File Download
|
|
78574
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in glucose 2 before stage 6.2 allows remote attackers to inject arbitrary web script or HTML via an RSS feed.
|
2012-01-23
|
glucose 2 RSS Feed XSS
|
|
72777
Description:
Unknown / Incomplete
|
2011-05-30
|
GluMobi Multiple Applications for Android Trojaned Distribution
|
|
65460
Description:
Unknown / Incomplete
|
2010-06-03
|
Gmail Checker Plus for Chrome Message Subject CSRF
|
|
65459
Description:
Unknown / Incomplete
|
2010-06-03
|
Gmail Checker Plus for Chrome Message Subject XSS
|
|
10940
Description:
Gmail Drive contains a flaw that may lead to an unauthorized information disclosure. The issue is due to the program naming the drive based on the Gmail account login name, resulting in a loss of confidentiality.
|
2004-10-19
|
Gmail Drive Local Account Name Disclosure
|
|
66884
Description:
Gmail-lite lets attackers do Mass Mailing, Mail Bombing, and Spamming. They don’t even need to set up a new Gmail-Lite server, nor write a complicated code for this. They simply can go to a Gmail-Lite web site, compose an abuse email, and send it to a victim thousands of times with just the aid of little extremely simple JavaScript. It creates DOS to other email users where their email systems don’t have smart and intelligent filter option like gmail;hence this vulnerability causes a huge impact to non-gmail users.
|
2008-03-01
|
Gmail-Lite compose.php Arbitrary Mail Relay
|
|
66886
Description:
The gmail-lite doesn't enforce the location and file permission of files uploaded so called attachments. Attacker can exploit this flaw to upload arbitrary PHP files which allow them to execute any functions that PHP can support such as command execution, file access, proxying ..etc/
|
2008-03-01
|
Gmail-Lite Unrestricted File Upload Arbitrary Code Execution
|
|
66885
Description:
Gmail-Lite contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate every GET/POST parameter upon submission to its scripts. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2008-01-01
|
Gmail-Lite Unspecified XSS
|
|
16171
Description:
Unknown / Incomplete
|
2005-05-01
|
GmailAgent Login Information Local Disclosure
|
|
47998
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the open_man_file function in callbacks.c in gmanedit 0.4.1 allows remote attackers to execute arbitrary code via a crafted man page, which is not properly handled during utf8 conversion. NOTE: another overflow was reported using a configuration file, but that vector does not have a scenario that crosses privilege boundaries.
|
2008-09-04
|
gmanedit callbacks.c open_man_file Function Crafted man Page Remote Overflow
|
|
39192
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.
|
2007-07-31
|
GMaps Component for Joomla! index.php viewmap Action mapId Parameter SQL Injection
|
|
76665
Description:
Unknown / Incomplete
|
2011-10-29
|
GMER 7201C008h IOCTL Parsing Local Privilege Escalation
|
|
62084
Description:
(Description Provided by CVE) : Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmime-encodings.h in GMime before 2.4.15 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via input data for a uuencode operation.
|
2010-01-31
|
GMime gmime/gmime-encodings.h GMIME_UUENCODE_LEN() Macro Uuencode Operation Overflow
|
|
2464
Description:
GBrowse contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the gbrowse script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the "help" variable.
|
2003-08-25
|
GMOD GBrowse gbrowse Arbitrary File Access
|
|
36571
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in showown.php in GMTT Music Distro 1.2 allows remote attackers to inject arbitrary web script or HTML via the st parameter.
|
2007-05-22
|
GMTT Music Distro showown.php st Parameter XSS
|
|
11875
Description:
Gnapster contains a flaw that may allow a malicious user to retrieve arbitrary files from a victim's computer because Gnapster fails to verify the shared status of files before sending them. The issue is triggered when a malicious user specifies the full path in a file request when using the GET command. It is possible that the flaw may allow arbitrary file retrieval resulting in a loss of confidentiality.
|
2000-05-10
|
Gnapster Absolute Path Name Request Arbitrary File Access
|
|
14341
Description:
(Description Provided by CVE) : Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files.
|
2002-02-12
|
GNAT Runtime Library Temp File Symlink Arbitrary File Modification
|
|
63622
Description:
Gnat-TGP contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'includes/tgpinc.php' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-03-03
|
Gnat-TGP includes/tgpinc.php DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
17759
Description:
(Description Provided by CVE) : gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.
|
2005-07-06
|
GNATS gen-index -o Parameter Arbitrary File Overwrite
|