| OSVDB ID | Disclosure Date | Title |
|
25045
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the agent_stats_pending_leads.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_stats_pending_leads.pl Multiple Parameter XSS
|
|
25026
Description:
Leadhound contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the agent_subaffiliates.pl script not properly sanitizing user-supplied input to the 'offset', 'camp_id' or 'sub' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-18
|
Leadhound agent_subaffiliates.pl Multiple Parameter SQL Injection
|
|
25043
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login', 'logged', 'offset', 'camp_id', 'date' or 'sub' variables upon submission to the agent_subaffiliates.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_subaffiliates.pl Multiple Parameter XSS
|
|
25048
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the the 'login', 'logged', 'offset' or 'date' variables upon submission to the agent_summary.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_summary.pl Multiple Parameter XSS
|
|
25028
Description:
Leadhound contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the agent_summary.pl script not properly sanitizing user-supplied input to the 'offset' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-18
|
Leadhound agent_summary.pl offset Parameter SQL Injection
|
|
25025
Description:
Leadhound contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the agent_transactions.pl script not properly sanitizing user-supplied input to the 'offset' or 'sub' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-18
|
Leadhound agent_transactions.pl Multiple Parameter SQL Injection
|
|
25046
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login', 'logged', 'offset', 'date' or 'sub' variables upon submission to the agent_transactions.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_transactions.pl Multiple Parameter XSS
|
|
25024
Description:
Leadhound contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the agent_transactions_csv.pl script not properly sanitizing user-supplied input to the 'sub' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-18
|
Leadhound agent_transactions_csv.pl sub Parameter SQL Injection
|
|
25050
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the Lost Password field upon submission to the lost_pwd.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound lost_pwd.pl Password Field XSS
|
|
25035
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the members.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound members.pl Multiple Parameter XSS
|
|
25038
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the modify_agent.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound modify_agent.pl Multiple Parameter XSS
|
|
25036
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the modify_agent_1.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound modify_agent_1.pl Multiple Parameter XSS
|
|
25037
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the modify_agent_2.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound modify_agent_2.pl Multiple Parameter XSS
|
|
25034
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' variable upon submission to the sign_out.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound sign_out.pl login Parameter XSS
|
|
36032
Description:
(Description Provided by CVE) : Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property.
|
2007-05-22
|
LEADTOOLS ISIS ActiveX (ltisi14E.ocx) DriverName Propery Overflow
|
|
36026
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the LEAD Technologies LeadTools JPEG 2000 LEADJ2K.LEADJ2K.140 ActiveX control (LTJ2K14.ocx) 14.5.0.35 allows remote attackers to execute arbitrary code via a long BitmapDataPath property.
|
2007-05-18
|
LEADTOOLS JPEG 2000 LEADJ2K.LEADJ2K.140 ActiveX (LTJ2K14.ocx) BitmapDataPath Property Overflow
|
|
36043
Description:
(Description Provided by CVE) : Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long DriverName property, a different ActiveX control than CVE-2007-2827.
|
2007-05-27
|
LEADTOOLS LEAD Raster ISIS Object ActiveX (LTRIS14e.DLL) DriverName Property Overflow
|
|
67692
Description:
The vulnerability is caused due to a boundary error in LtocxTwainu.dll when handling the value assigned to the "AppName" property and can be exploited to cause a heap-based buffer overflow via an overly long string. Successful exploitation allows execution of arbitrary code.
|
2010-08-28
|
LEADTOOLS LEAD RasterTwain LtocxTwainu.dll ActiveX AppName Property Overflow
|
|
43746
Description:
(Description Provided by CVE) : The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow attackers to overwrite arbitrary files via the SaveSettingsToFile method.
|
2008-03-25
|
LEADTOOLS Multimedia Library ActiveX (ltmm15.dll) Multiple Class SaveSettingsToFile() Method Arbitrary File Overwrite
|
|
36035
Description:
(Description Provided by CVE) : Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows remote attackers to execute arbitrary code via a long Directory property value.
|
2007-05-24
|
LEADTOOLS Raster Dialog File Object ActiveX (LTRDF14e.DLL) Directory Property Overflow
|
|
36036
Description:
(Description Provided by CVE) : Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long DestinationPath property value.
|
2007-05-25
|
LEADTOOLS Raster Dialog File_D Object ActiveX (LTRDFD14e.DLL) DestinationPath Property Overflow
|
|
36042
Description:
(Description Provided by CVE) : Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote attackers to execute arbitrary code via a long DictionaryFileName property.
|
2007-05-26
|
LEADTOOLS Raster OCR Document Object Library ActiveX (ltrdc14e.dll) DictionaryFileName Property Overflow
|
|
36029
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object Library 14.5.0.44 allows remote attackers to execute arbitrary code via a long argument.
|
2007-05-20
|
LEADTOOLS Raster Thumbnail Object Library ActiveX (LTRTM14e.DLL) BrowseDir Function Overflow
|
|
36028
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object Library 14.5.0.44 allows remote attackers to execute arbitrary code via a long argument.
|
2007-05-19
|
LEADTOOLS Raster Thumbnail Object Library ActiveX (lttmb14E.ocx) BrowseDir Ffunction Overflow
|
|
36033
Description:
(Description Provided by CVE) : A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to overwrite arbitrary files via the WriteDataToFile method.
|
2007-05-21
|
LEADTOOLS Raster Variant Object Library ActiveX (LTRVR14e.dll) WriteDataToFile Method Arbitrary File Overwrite
|
|
1426
Description:
(Description Provided by CVE) : LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.
|
2000-06-25
|
LeafDigital LeafChat Error Message Flood DoS
|
|
16568
Description:
(Description Provided by CVE) : The leafnode server in leafnode 1.9.20 to 1.9.29 allows remote attackers to cause a denial of service (infinite loop) when leafnode requests a cross-posted article to one group whose name is a prefix of another group.
|
2002-12-29
|
leafnode Cross-Posted Article Group Name Prefix DoS
|
|
16187
Description:
(Description Provided by CVE) : fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers.
|
2005-05-04
|
leafnode fetchnews Article Transfer Disconnect DoS
|
|
6452
Description:
(Description Provided by CVE) : The fetchnews NNTP client in leafnode 1.9.3 to 1.9.41 allows remote attackers to cause a denial of service (process hang and termination) via certain malformed Usenet news articles that cause fetchnews to hang while waiting for input.
|
2003-09-04
|
leafnode fetchnews Client Malformed Usenet Post DoS
|
|
2515
Description:
Unknown / Incomplete
|
2003-09-05
|
leafnode Malformed Data Send DoS
|