| OSVDB ID | Disclosure Date | Title |
|
21439
Description:
Warm Links contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'search' variable upon submission to the 'search.cgi' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-05
|
Warm Links search.cgi search Parameter XSS
|
|
16802
Description:
Warrior Kings: Battles contains a flaw that may allow a remote denial of service. The issue is triggered when sending a malformed join packet, which causes the server to crash resulting in a loss of availability.
|
2005-05-23
|
Warrior Kings: Battles Malformed Join Packet DoS
|
|
16801
Description:
Warrior Kings and Warrior Kings: Battles contains a flaw that may allow a remote attacker to execute arbitrary code. The issue is triggered due to a format string error in the text visualization. With a specially crafted nickname, a remote attacker may execute arbitrary code resulting in a loss of integrity.
|
2005-05-23
|
Warrior Kings: Battles Nickname Remote Format String
|
|
36721
Description:
(Description Provided by CVE) : Buffer overflow in Warzone 2100 Resurrection before 2.0.7 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename when setting background music.
|
2007-06-22
|
Warzone 2100 Resurrection Background Music File Handling Overflow
|
|
36720
Description:
Unknown / Incomplete
|
2006-08-25
|
Warzone 2100 Resurrection Multiple Unspecified Issues
|
|
27910
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Warzone 2100 and Warzone Resurrection 2.0.3 and earlier allows remote attackers to execute arbitrary code via a (1) long message handled by the recvTextMessage function in multiplay.c or a (2) long filename handled by NETrecvFile function in netplay/netplay.c.
|
2006-07-23
|
Warzone Resurrection multiplay.c recvTextMessage Function Overflow
|
|
27911
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Warzone 2100 and Warzone Resurrection 2.0.3 and earlier allows remote attackers to execute arbitrary code via a (1) long message handled by the recvTextMessage function in multiplay.c or a (2) long filename handled by NETrecvFile function in netplay/netplay.c.
|
2006-07-23
|
Warzone Resurrection netplay.c NETrecvFile Function Overflow
|
|
21288
Description:
WASD WebServer PerlRTE_example1.pl contains a format string flaw. The issue is triggered when a user sends malcious input via format string errors in the $name variable. It is possible that the flaw may allow arbitrary code execution and/or a denial of service.
|
2005-11-29
|
WASD Web Server PerlRTE_example1.pl name Variable Format String
|
|
40854
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.
|
2008-01-30
|
WassUp Plugin for WordPress spy.php Multiple Parameter SQL Injection
|
|
61023
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Watchdog (aba_watchdog) extension 2.0.2 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.
|
2009-12-15
|
Watchdog Extension for TYPO3 Unspecified Information Disclosure
|
|
68926
Description:
Watcher Module for Drupal contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the subscribe and unsubscribe actions. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-10-29
|
Watcher Module for Drupal Multiple Function CSRF
|
|
68925
Description:
Watcher Module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-10-29
|
Watcher Module for Drupal Unspecified XSS
|
|
21746
Description:
(Description Provided by CVE) : Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.
|
2005-12-15
|
Watchfire AppScan QA 401 HTTP Response Overflow
|
|
44872
Description:
(Description Provided by CVE) : Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) CompactSave and (2) SaveSession method in one control, and the (3) saveRecordedExploreToFile method in a different control. NOTE: this can be leveraged for code execution by writing to a Startup folder.
|
2008-04-25
|
WatchFire AppScan Unspecified ActiveX Multiple Method Traversal Arbitrary File Overwrite
|
|
5004
Description:
(Description Provided by CVE) : Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to TCP port 4110.
|
2002-07-09
|
WatchGuard Firebox DVCP Malformed Packet DoS
|
|
1648
Description:
WatchGuard Firebox II contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker floods the server with FTP or SMTP requests, disabling subsequent proxy handling.
|
2000-11-16
|
WatchGuard Firebox II FTP/SMTP Proxy DoS
|
|
1740
Description:
Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication.
|
2001-01-20
|
WatchGuard Firebox II Hashed Passphrase Disclosure Local Privilege Escalation
|
|
6438
Description:
Watchguard Firebox II contains a flaw that may allow a remote denial of service. The issue is due to the kernel of Firebox II not properly handling malformed TCP or ICMP packets. By sending a large stream (>10,000) of malformed ICMP or TCP packets, a remote attacker can crash or reboot the system, resulting in loss of availability.
|
2001-04-05
|
WatchGuard Firebox II ICMP/TCP Large Stream DoS
|
|
1512
Description:
(Description Provided by CVE) : Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100.
|
2000-08-15
|
WatchGuard Firebox II Port 4100 Malformed URL Remote DoS
|
|
1761
Description:
(Description Provided by CVE) : Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.
|
2001-02-14
|
WatchGuard Firebox ll Multiple Connection Malformed PPTP DoS
|
|
44218
Description:
(Description Provided by CVE) : The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.
|
2008-04-04
|
WatchGuard Firebox Products PPTP VPN Service Username Enumeration
|
|
1863
Description:
(Description Provided by CVE) : SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes.
|
2001-06-08
|
WatchGuard Firebox SMTP Proxy Attachment Bypassing
|
|
4401
Description:
WatchGuard Firebox SOHO contains a flaw that may allow a remote attacker to remotely change the administrative password. The issue is due to a flaw in the authentication mechanism of the device, which allows a blank unauthenticated request to the /passcfg object. Such a request will reset the password to an empty field allowing the attacker to use any administrative options without having to provide authentication credentials.
|
2000-12-14
|
WatchGuard Firebox SOHO Administrator Password Remote Reset
|
|
1690
Description:
WatchGuard Firebox SOHO contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker sends a large amount of fragmented packets, and will result in loss of availability for the firewall.
|
2000-12-14
|
WatchGuard Firebox SOHO Fragmented IP Packet DoS
|
|
4403
Description:
WatchGuard Firebox SOHO contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends an overly long GET request to the Web administration interface, and will result in loss of availability for the firewall.
|
2000-12-14
|
WatchGuard Firebox SOHO GET Request Overflow DoS
|
|
4407
Description:
WatchGuard Firebox SOHO contains a flaw that may allow a remote attacker to gain access to the FTP service. The issue is due to the FTP service not requiring a valid user name to log in. This allows an attacker to more easily brute force a valid password without the need of a matching account. If compromised, the firewall configuration and other sensitive information could be downloaded.
|
2002-07-01
|
WatchGuard Firebox SOHO Insecure FTP Authentication
|
|
4405
Description:
WatchGuard Firebox SOHO contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker sends IP packets with invalid IP options set which will crash the firewall resulting in a loss of availability.
|
2002-04-08
|
WatchGuard Firebox SOHO Invalid IP Options DoS
|
|
4406
Description:
WatchGuard Firebox SOHO contains a flaw that may allow an attacker to access protected custom services. The issue is due to a non-descript flaw that causes IP restrictions for custom services to intermittently fail.
|
2002-04-10
|
WatchGuard Firebox SOHO IP Restriction Bypass
|
|
4402
Description:
WatchGuard Firebox SOHO contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker sends a large number of GET requests to the web server, and will result in loss of availability for the firewall.
|
2000-12-04
|
WatchGuard Firebox SOHO Multiple HTTP GET Request DoS
|
|
59954
Description:
(Description Provided by CVE) : WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.
|
2002-10-10
|
WatchGuard Firebox SOHO Products PASV Command FTP Ruleset Bypass
|