| OSVDB ID | Disclosure Date | Title |
|
32995
Description:
(Description Provided by CVE) : T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value.
|
2007-01-19
|
T-Com Speedport 500V Series LOGINKEY=TECOM Cookie Value Authentication Bypass
|
|
36011
Description:
(Description Provided by CVE) : Deutsche Telekom (T-com) Speedport W 700v uses JavaScript delays for invalid authentication attempts to the CGI script, which allows remote attackers to bypass the delays and conduct brute-force attacks via direct calls to the authentication CGI script.
|
2007-05-11
|
T-Com Speedport W 700v Login Brute Force Weakness
|
|
58452
Description:
T-HTB Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' and 'name' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-09-10
|
T-HTB Manager index.php Multiple Parameter SQL Injection
|
|
34986
Description:
(Description Provided by CVE) : T-Mobile voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).
|
2007-01-30
|
T-Mobile Voice Mail Calling Number Identification (CNID) Spoofing Arbitrary Mailbox Manipulation
|
|
61235
Description:
(Description Provided by CVE) : Unspecified vulnerability in t-prot (TOFU Protection) before 2.8 allows remote attackers to cause a denial of service via unspecified vectors related to the "--maxlines" option and a crafted email message. NOTE: some of these details are obtained from third party information.
|
2009-12-20
|
t-prot (TOFU Protection) for Mutt --max-lines Unspecified DoS
|
|
61293
Description:
Unknown / Incomplete
|
2003-06-24
|
t-prot (TOFU Protection) for Mutt Crafted Multipart Message Handling DoS
|
|
61292
Description:
Unknown / Incomplete
|
2002-10-31
|
t-prot (TOFU Protection) for Mutt Symlink Arbitrary File Overwrite
|
|
33966
Description:
(Description Provided by CVE) : SQL injection vulnerability in logout.php in T.G.S. CMS 0.1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the myauthorid cookie.
|
2006-10-31
|
T.G.S. CMS logout.php myauthorid Cookie SQL Injection
|
|
74334
Description:
WPtouch Plugin for WordPress has a compromised download which contains a trojaned backdoor with may allow an attacker to conduct XSS attacks or have other unspecified impact.
|
2011-04-05
|
t00ls.org c100 Shell Trojaned Distribution
|
|
38698
Description:
(Description Provided by CVE) : Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.
|
2007-07-27
|
t1lib lib/t1lib/t1env.c intT1_EnvGetCompletePath() Function Overflow
|
|
74527
Description:
(Description Provided by CVE) : t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6 and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.
|
2011-03-21
|
t1lib PDF Type 1 Font Handling Invalid Memory Location DoS
|
|
74528
Description:
(Description Provided by CVE) : Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6 and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
|
2011-03-21
|
t1lib PDF Type 1 Font Handling Invalid Memory Write Use-after-free DoS
|
|
72302
Description:
A memory corruption flaw exists in t1lib. The font handling function fails to sanitize user-supplied input using Type 1 fonts resulting in memory corruption. With a specially crafted PDF file, a context-dependent attacker can execute arbitrary code.
|
2011-03-22
|
t1lib PDF Type 1 Font Handling Invalid Pointer Code Execution
|
|
74526
Description:
(Description Provided by CVE) : Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6 and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.
|
2011-03-21
|
t1lib PDF Type 1 Font Handling Off-by-one Overflow DoS
|
|
23193
Description:
Unknown / Incomplete
|
2004-12-30
|
T2 binutils/ld-glob.patch Unspecified Memory Corruption Issue
|
|
23194
Description:
Unknown / Incomplete
|
2004-12-31
|
T2 Build-Pkg /bin/cat List Argument Local Overflow
|
|
23196
Description:
Unknown / Incomplete
|
2005-12-30
|
T2 extend_initrd Unspecified Path Disclosure
|
|
23195
Description:
Unknown / Incomplete
|
2005-08-11
|
T2 gnomesu/feature.patch Local Password Disclosure
|
|
23192
Description:
Unknown / Incomplete
|
2004-04-18
|
T2 linux24benh Kernel Unspecified Issues
|
|
75943
Description:
Unknown / Incomplete
|
2011-09-27
|
T3BLOG Extension for TYPO3 Comment Parent Title Unspecified XSS
|
|
62074
Description:
T3BLOG Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to an unspecified script not properly sanitizing user-supplied input. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-01
|
T3BLOG Extension for TYPO3 Unspecified SQL Injection
|
|
62075
Description:
T3BLOG Extension for TYPO3 contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate unspecified input upon submission to an unspecified script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-01
|
T3BLOG Extension for TYPO3 Unspecified XSS
|
|
66682
Description:
(Description Provided by CVE) : SQL injection vulnerability in the T3M E-Mail Marketing Tool (t3m) extension 0.2.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
2009-08-18
|
T3M E-Mail Marketing Tool for TYPO3 Unspecified SQL Injection
|
|
66692
Description:
(Description Provided by CVE) : SQL injection vulnerability in the t3m_affiliate extension 0.5.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
2009-08-18
|
t3m_affiliate Extension for TYPO3 Unspecified SQL Injection
|
|
63038
Description:
t3sec_saltedpw contains a flaw related to the frontend authentication that may allow an attacker to bypass authentication. No further details have been provided.
|
2010-03-16
|
t3sec_saltedpw Extension for TYPO3 Unspecified Extension Bypass
|
|
77352
Description:
Unknown / Incomplete
|
2011-11-23
|
TA.CMS (TeachArabia) index.php id Parameter SQL Injection
|
|
77353
Description:
Unknown / Incomplete
|
2011-11-23
|
TA.CMS (TeachArabia) lang Parameter Traversal Local File Inclusion
|
|
64360
Description:
Table JX contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate "data_search' and 'rpp' parameters upon submission to the index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-01
|
Table JX Component for Joomla! index.php Multiple Parameter XSS
|
|
19479
Description:
TRAC Vista Webstation contains a flaw that allows a remote attacker to traverse outside of the web path. The issue is due to the ISALogin.dll program not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the Template variable.
|
2005-09-16
|
TAC Vista ISALogin.dll Template Parameter Traversal Arbitrary File Access
|
|
8848
Description:
(Description Provided by CVE) : tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files.
|
2002-01-30
|
tac_plus Tacacs+ Daemon Arbitrary File Modification
|