| OSVDB ID | Disclosure Date | Title |
|
6501
Description:
Debian Gatos contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an administrator removes the Gates default configuration file, root privileges are not dropped on xativ initialization, and xatitv executes the system(3) function to launch its configuration program without sanitizing user-supplied environment variables. This flaw may lead to a loss of Confidentiality.
|
2004-05-31
|
Debian GATOS xatitv Initialization Privilege Escalation
|
|
6577
Description:
Linksys routers contain a flaw that may allow a malicious user to access the Remote Administration interface. The issue is triggered by the interface being available on port 443, even when Remote Administration is disabled. It is possible that the flaw may allow unauthorized administrative access resulting in a loss of integrity.
|
2004-05-31
|
Cisco Linksys Routers Administrative Web Interface Access
|
|
6492
Description:
The jftpgw proxy server contains a flaw that may allow an attacker to execute arbitrary commands with the privileges of the server process. The issue is caused by an error in the logging functionality of the server where user supplied data is passed as a format string directly to a syslog() function call.
|
2004-05-30
|
jftpgw syslog() Logging Format String
|
|
55372
Description:
(Description Provided by CVE) : Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.
|
2004-05-30
|
Horde IMP mime.php Content-Type XSS
|
|
55373
Description:
Unknown / Incomplete
|
2004-05-30
|
OpenWebmail mime.php Content-Type XSS
|
|
55374
Description:
(Description Provided by CVE) : Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.
|
2004-05-30
|
IlohaMail mime.php Content-Type XSS
|
|
55375
Description:
(Description Provided by CVE) : Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.
|
2004-05-30
|
Sqwebmail mime.php Content-Type XSS
|
|
55376
Description:
(Description Provided by CVE) : Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.
|
2004-05-30
|
BasiliX mime.php Content-Type XSS
|
|
8292
Description:
SquirrelMail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "$senderNames_part", "$event_title", or "$event_text" variables upon submission to the "mailbox_display.php" script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-05-30
|
SquirrelMail mailbox_display.php Multiple Parameter XSS
|
|
54626
Description:
Unknown / Incomplete
|
2004-05-29
|
Open WebMail (OWM) E-mail Multiple Content Header XSS
|
|
7613
Description:
PHPhoto contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered due to the 'picture_controls.php' script, which will disclose hidden pictures by unauthorized users resulting in a loss of confidentiality.
|
2004-05-29
|
PHPoto picture_controls.php Hidden Picture Disclosure
|
|
9967
Description:
Unknown / Incomplete
|
2004-05-29
|
Mozilla Multiple Products nsPop3Protocol.cpp msg_info Overflow
|
|
6525
Description:
e107 contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when scripts are accessed directly and generate a PHP error, which will disclose the full path of the requested script resulting in a loss of confidentiality.
|
2004-05-29
|
e107 Multiple Menu Path Disclosure
|
|
6526
Description:
e107 contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate variables upon submission to the clock_menu.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-05-29
|
e107 clock_menu.php LAN_407 Parameter XSS
|
|
6527
Description:
e107 contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate "logged name" variables upon submission to the "email article to a friend" feature. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-05-29
|
e107 "email article to a friend" Feature XSS
|
|
6528
Description:
e107 contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate "logged name" variables upon submission to the "submit news" feature. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-05-29
|
e107 "submit news" Feature XSS
|
|
6529
Description:
e107 contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "avmsg" variable upon submission to the "usersettings.php" script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-05-29
|
e107 usersettings.php avmsg Parameter XSS
|
|
6530
Description:
e107 contains a flaw that may allow arbitrary command execution. The issue is triggered when the "p" parameter in the script "secure_img_render.php" is not properly verified. It is possible that the flaw may allow a malicious user to include arbitrary scripts and files from local or remote resources which will be executed on the vulnerable server, resulting in a loss of integrity.
|
2004-05-29
|
e107 secure_img_render.php p Parameter Remote File Inclusion
|
|
6531
Description:
e107 contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'content.php' script not properly sanitizing user-supplied input to the 'content' and 'content_id' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2004-05-29
|
e107 content.php Multiple Parameter SQL Injection
|
|
6508
Description:
Land Down Under (LDU) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate [img] BBCode tags upon submission to various scripts. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-05-29
|
Land Down Under (LDU) BBCode IMG Tag XSS
|
|
6533
Description:
e107 contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "list" variable in the news.php script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-05-29
|
e107 news.php list Parameter SQL Injection
|
|
6514
Description:
Multiple Webmail products contain a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate Content-Type upon submission to the mime.php script (or whatever script controls header content-type). This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-05-29
|
SquirrelMail mime.php Content-Type XSS
|
|
10959
Description:
MySQL contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when that users is given GRANT privileges on a database whose name contains an underscore, i.e. database_name. The underscore is treated as a wildcard; continuing the example, the user would then have GRANT privileges on database1name, databaseZname, etc. This flaw may lead to a loss of confidentiality and/or integrity.
|
2004-05-29
|
MySQL GRANT ALL ON Privilege Escalation
|
|
6752
Description:
Unknown / Incomplete
|
2004-05-29
|
pkt Unspecified Logfile Permissions
|
|
6503
Description:
jPORTAL contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the id parameter in the art_print() function in the print.inc.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-05-29
|
jPortal print.inc.php id Parameter SQL Injection
|
|
8291
Description:
SquirrelMail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables upon submission to the 'read_body.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-05-29
|
SquirrelMail read_body.php Multiple Parameter XSS
|
|
11189
Description:
A bandwidth monitor, bmon, on FreeBSD contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the FreeBSD port system installs bmon with setuid superuser privileges.
|
2004-05-29
|
FreeBSD bmon Port Relative Path Subversion Privilege Escalation
|
|
6521
Description:
Multiple remote overflows exist in spamGuard. The qmail_parseline and sendmail_parseline functions in parser.c fail to validate input resulting in buffer overflows. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2004-05-28
|
spamGuard parser.c Multiple Remote Overflows
|
|
6522
Description:
Multiple local overflows exist in spamGuard. The loadconfig and removespaces functions in loadconfig.c fail to validate input resulting in buffer overflows. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2004-05-28
|
spamGuard loadconfig.c Multiple Overflows
|
|
6523
Description:
Multiple local overflows exist in spamGuard. Unspecified functions in functions.c fail to validate input resulting in buffer overflows. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity. No further details have been provided.
|
2004-05-28
|
spamGuard functions.c Overflow
|
|
6755
Description:
Unknown / Incomplete
|
2004-05-28
|
Hydra Backup System Unspecified Quote Based
|
|
7585
Description:
The ia64 Linux Kernel contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a floating point leak occurs, which will disclose the registers of other process information resulting in a loss of confidentiality.
|
2004-05-28
|
Linux Kernel MFH Bit Information Disclosure
|
|
6446
Description:
Sun Java System Application Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when HTTP GET requests containing multiple slashes and reserved DOS device names are received, which will disclose the absolute path of the document root, resulting in a loss of confidentiality.
|
2004-05-28
|
Sun Java System Application Server HTTP Error Page Path Disclosure
|
|
6657
Description:
Sophster contains a flaw that may allow a malicious user to modify file attributes. The issue is triggered when the change permissions tool is used on files with special UID/GID and sticky bits. It is possible that the flaw may allow arbitrary file access resulting in a loss of confidentiality.
|
2004-05-28
|
Sophster Change Permission Function
|
|
7421
Description:
(Description Provided by CVE) : Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
|
2004-05-27
|
Linux Kernel Multiple Unspecified Issues
|
|
18567
Description:
(Description Provided by CVE) : Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password. NOTE: this identifier was inadvertently re-used for another issue due to a typo; that issue was assigned CVE-2004-0447. This candidate is ONLY for the ADSL router bypass.
|
2004-05-27
|
3Com OfficeConnect 812 ADSL Router Authentication Bypass
|
|
6433
Description:
HP OpenView contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the product fails to decode a UTF-8 input correctly. This flaw may lead to a loss of confidentiality and integrity.
|
2004-05-27
|
HP OpenView Select Access UTF-8 Decoding Access Restriction Bypass
|
|
6691
Description:
Roundup contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the program not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the @@file prefix.
|
2004-05-27
|
Roundup @@file GET Request Arbitrary File Access
|
|
7218
Description:
(Description Provided by CVE) : Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.
|
2004-05-27
|
Linux Kernel Unspecified Memory Disclosure
|
|
6425
Description:
FreeBSD 5.2 and prior contains a flaw that may allow a malicious user to prevent file writes to disk. The issue is triggered when a user with read access to a file takes advantage of the errrors in the msync(2) system call involving the MS_INVALIDATE operation. It is possible that the flaw may allow changes from being committed to disk resulting in a loss of integrity, and availability.
|
2004-05-26
|
FreeBSD msync MS_INVALIDATE File Write Restriction
|