| OSVDB ID | Disclosure Date | Title |
|
59809
Description:
(Description Provided by CVE) : Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.
|
2003-01-31
|
SILC Client Cleartext Password / Session Memory Dump Local Disclosure
|
|
60272
Description:
(Description Provided by CVE) : SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.
|
2003-01-31
|
SpamProbe HTML Email href Tag Newline Handling Remote DoS
|
|
20143
Description:
Unknown / Incomplete
|
2003-01-30
|
lmtp2nntp l2_spec() Function Format String
|
|
7117
Description:
A remote overflow exists in Windows. The RPC Locator service fails to validate search requests resulting in a stack overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2003-01-30
|
Microsoft Windows RPC Locator Remote Overflow
|
|
3592
Description:
dotProject contains a flaw that allows a remote attacker to include arbitrary files. The issue is due to numerous scripts that call the classdefs/date.php script without defining or restricting the $root_dir variable. This allows an attacker to set the variable to an arbitrary server/path/file name which may include malicious commands that would be executed on the vulnerable server.
|
2003-01-29
|
dotProject classdefs/date.php $root_dir Arbitrary File Include
|
|
13809
Description:
(Description Provided by CVE) : Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.
|
2003-01-29
|
plptools plpnfsd Logging Format String Overflow
|
|
34670
Description:
WU-FTPD contains a flaw that may allow a remote attacker to cause a Denial of Service condition. The issue occurs when WU-FTPD is compiled on certain unspecified operating systems that limit non-connected socket binds to the same local address. In such a situation, a remote attacker can exhaust the connection resources preventing further legitimate connections.
|
2003-01-29
|
WU-FTPD on Unspecified OS Connection Saturation DoS
|
|
19786
Description:
(Description Provided by CVE) : X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.
|
2003-01-28
|
Multiple Java Package X509TrustManager isClientTrusted Method Trust Failure
|
|
4887
Description:
(Description Provided by CVE) : Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.
|
2003-01-28
|
MIT Kerberos 5 Key Distribution Center (KDC) chk_trans.c libkrb5 Cross-realm Impersonation
|
|
20090
Description:
(Description Provided by CVE) : BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
|
2003-01-28
|
BEA WebLogic server.same Buffer Cleartext Password Disclosure
|
|
4879
Description:
MIT Kerberos Key Distribution Center (KDC) contains a flaw that may allow a remote attacker to crash the service and possibly execute arbitrary code. The issue is due to format string flaws in the logging routines and Kerberos principal name specifiers of the KDC. If an attacker provides a specially crafted request, they can crash the service or execute arbitrary code with the same privilege the server runs under.
|
2003-01-28
|
MIT Kerberos 5 Key Distribution Center Format String Logging
|
|
4896
Description:
A remote overflow exists in MIT Kerberos 5. The ASN.1 decoder fails to properly sanitize user suplied input resulting in heap corruption. If an attacker sends a specially crafted packet with a negative length value, they may cause the services to crash resulting in a loss of availability.
|
2003-01-28
|
MIT Kerberos 5 ASN.1 Decoder Heap Corruption DoS
|
|
4898
Description:
Various FTP clients contain a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered due to an input validation error in the ftp client when handling filenames. By sending a specially crafted filename beginning with a pipe character ("|") a malicous user could execute arbitrary code resulting in a loss of integrity.
|
2003-01-28
|
Multiple Vendors FTP Client Pipe Character Arbitrary Code Execution
|
|
7685
Description:
(Description Provided by CVE) : SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
|
2003-01-28
|
Van Dyke SSH2 Client Memory Logon Credential Leak
|
|
7686
Description:
AbsoluteTelnet SSH2 Client contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to plaintext passwords stored in memory when a search of memery is performed, which may lead to a loss of confidentiality.
|
2003-01-28
|
AbsoluteTelnet SSH2 Client Memory Logon Credential Leak
|
|
7687
Description:
(Description Provided by CVE) : PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
|
2003-01-28
|
PuTTY SSH2 Client Memory Logon Credential Leak
|
|
7688
Description:
(Description Provided by CVE) : SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
|
2003-01-28
|
WinSCP Client Memory Logon Credential Leak
|
|
58669
Description:
Unknown / Incomplete
|
2003-01-28
|
Apache Jetspeed LDAP Cleartext Passwords Disclosure
|
|
60386
Description:
(Description Provided by CVE) : Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.
|
2003-01-28
|
BEA WebLogic Server Session Replication Cross-user Session Information Disclosure
|
|
91765
Description:
dpkg contains a flaw when handling the -b argument as the program creates temporary files insecurely. It is possible for a local attacker to use a symlink attack against the dpkg-source file to cause the program to unexpectedly overwrite an arbitrary file.
|
2003-01-28
|
dpkg dpkg-source -b Argument Symlink Arbitrary File Overwrite
|
|
15143
Description:
(Description Provided by CVE) : Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.
|
2003-01-27
|
Solaris in.ftpd Unspecified Remote DoS
|
|
15142
Description:
(Description Provided by CVE) : A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.
|
2003-01-27
|
Solaris at -r Argument Race Condition Arbitrary File Deletion
|
|
58499
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.
|
2003-01-27
|
Nuked-Klan Guestbook Module Author Field XSS
|
|
58500
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.
|
2003-01-27
|
Nuked-Klan Forum Module Multiple Field XSS
|
|
58501
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.
|
2003-01-27
|
Nuked-Klan Shoutbox Module La Tribune Libre XSS
|
|
4820
Description:
ThWboard contains a flaw that may allow arbitrary data to be deleted. The issue is due to a flaw in the pm.php script. No further details have been provided.
|
2003-01-27
|
ThWboard pm.php Arbitrary Data Deletion
|
|
4821
Description:
ThWboard contains a flaw that may allow arbitrary data to be deleted. The issue is due to a flaw in the postops.php script. No further details have been provided.
|
2003-01-27
|
ThWboard postops.php Arbitrary Data Deletion
|
|
13487
Description:
(Description Provided by CVE) : Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.
|
2003-01-27
|
Noffle News Server Multiple Unspecified Overflows
|
|
14559
Description:
(Description Provided by CVE) : Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.
|
2003-01-27
|
Hypermail Long Attachment Filename Overflow
|
|
14560
Description:
(Description Provided by CVE) : Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.
|
2003-01-27
|
Hypermail Mail CGI Long Hostname Lookup Overflow
|
|
40806
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.
|
2003-01-27
|
Nukebrowser nukebrowser.php filhead Parameter Remote File Inclusion
|
|
59615
Description:
(Description Provided by CVE) : ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.
|
2003-01-27
|
ProxyView Embedded Windows NT Default Admin Account Password
|
|
3593
Description:
dotProject contains a flaw that allows a remote attacker to read arbitrary files. The issue is due to the core.php script calling the classdefs/date.php script without defining or restricting the $root_dir variable. This allows an attacker to set the variable to an arbitrary file or directory, terminate the request with %00, and have the file displayed.
|
2003-01-26
|
dotProject core.php Read Arbitrary File
|
|
9203
Description:
Jakarta Tomcat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables in examples applications. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-01-25
|
Apache Tomcat examples Application XSS
|
|
9204
Description:
Jakarta Tomcat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables in "ROOT" application. No further description is available. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-01-25
|
Apache Tomcat ROOT Application XSS
|
|
12231
Description:
Jakarta Tomcat contains a flaw that may lead to an unauthorized information disclosure. The issue is due to an error when using trusted privileges to process the web.xml file. This flaw may allow a remote attacker to use web.xml to read arbitrary files in the web server, resulting in a loss of confidentiality.
|
2003-01-25
|
Apache Tomcat web.xml Arbitrary File Access
|
|
12232
Description:
(Description Provided by CVE) : Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
|
2003-01-25
|
Apache Tomcat with JDK Arbitrary Directory/Source Disclosure
|
|
59446
Description:
FTLS.org Guestbook contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'comment', 'name', or 'title' parameters upon submission to the 'guestbook.cgi' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2003-01-25
|
FTLS.org Guestbook guestbook.cgi Multiple Parameter XSS
|
|
53674
Description:
Unknown / Incomplete
|
2003-01-24
|
YaBB SE News.php template Parameter Remote File Inclusion
|
|
56290
Description:
(Description Provided by CVE) : Directory traversal vulnerability in edittag.cgi in EditTag 1.1 allows remote attackers to read arbitrary files via a "%2F.." (encoded slash dot dot) in the file parameter.
|
2003-01-24
|
EditTag edittag.cgi file Parameter Encoded Traversal Arbitrary File Access
|