| OSVDB ID | Disclosure Date | Title |
|
31702
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the ole_info_read_metabat function in Gnome Structured File library (libgsf) 1.14.0, and other versions before 1.14.2, allows context-dependent attackers to execute arbitrary code via a large num_metabat value in an OLE document, which causes the ole_init_info function to allocate insufficient memory.
|
2006-11-30
|
GNOME Structured File Library (libgsf) ole_info_read_metabat() Function Overflow
|
|
30724
Description:
(Description Provided by CVE) : Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Core Duo hardware allows remote attackers to cause a denial of service (out-of-bounds memory access and kernel panic) and have possibly other security-related impact via certain beacon frames.
|
2006-11-30
|
Apple AirPort Beacon Frame Handling DoS
|
|
31781
Description:
A remote overflow exists in NetBSD and Mac OS X. The glob.c implementation in ftpd daemon fails to validate long pathnames resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-11-30
|
Apple Mac OS X and NetBSD ftpd Globbing Overflow
|
|
31718
Description:
(Description Provided by CVE) : Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors, possibly related to the exitlwps function and SIGKILL and /proc PCAGENT signals.
|
2006-11-30
|
Solaris Kernel Unspecified Race Condition Local DoS
|
|
31716
Description:
(Description Provided by CVE) : Directory traversal vulnerability in admin/FileServer.php in ContentServ 4.x allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter, a different vector than CVE-2005-3086.
|
2006-11-30
|
ContentServ admin/FileServer.php src Parameter Traversal Arbitrary File Access
|
|
31803
Description:
(Description Provided by CVE) : The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration. NOTE: vector 1 might be the same as CVE-2006-5290.
|
2006-11-30
|
XEROX WorkCentre Products Web User Interface TCP/IP Hostname Command Injection
|
|
31804
Description:
(Description Provided by CVE) : The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration. NOTE: vector 1 might be the same as CVE-2006-5290.
|
2006-11-30
|
XEROX WorkCentre Products Web User Interface Scan-to-mailbox Folder Name Command Injection
|
|
31805
Description:
(Description Provided by CVE) : The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration. NOTE: vector 1 might be the same as CVE-2006-5290.
|
2006-11-30
|
XEROX WorkCentre Products Web User Interface Microsoft Networking Configuration Command Injection
|
|
31806
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allow remote attackers to gain access via unspecified vectors related to "browser permissions."
|
2006-11-30
|
XEROX WorkCentre Products Browser Permissions Unspecified Privilege Escalation
|
|
31807
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows attackers to modify certain configuration settings via unspecified vectors involving the "TFTP/BOOTP auto configuration option."
|
2006-11-30
|
XEROX WorkCentre Products TFTP/BOOTP Auto Configuration Unspecified Issue
|
|
31808
Description:
(Description Provided by CVE) : Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensitive information by sniffing the unencrypted HTTP traffic.
|
2006-11-30
|
XEROX WorkCentre Products Web Services Request Persistant HTTP Connection
|
|
31809
Description:
(Description Provided by CVE) : Unspecified vulnerability in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows attackers to modify signatures of e-mail messages via unspecified vectors.
|
2006-11-30
|
XEROX WorkCentre Products E-mail Signature Content Injection
|
|
31810
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Scan-to-mailbox feature in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to download certain files via unspecified vectors.
|
2006-11-30
|
XEROX WorkCentre Products Scan-to-mailbox Feature Arbitrary File Access
|
|
31811
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 does not record accurate timestamps, which makes it easier for remote attackers to avoid detection when an audit tries to rely on these timestamps.
|
2006-11-30
|
XEROX WorkCentre Products Audit Log Timestamp Failure
|
|
31812
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to bypass authentication controls via unknown vectors.
|
2006-11-30
|
XEROX WorkCentre Products Web User Interface Authentication Bypass
|
|
31813
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 have unknown impact and attack vectors, related to (1) an Immediate Image Overwrite (IIO) error message at the Local User Interface (LUI) if overwrite fails, (2) an IIO failure when a Held Job is deleted, and (3) an On Demand Image Overwrite failure when the overwrite is greater than 2 Gb.
|
2006-11-30
|
XEROX WorkCentre Products LUI Overwrite Failure IIO Error Message
|
|
31814
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 have unknown impact and attack vectors, related to (1) an Immediate Image Overwrite (IIO) error message at the Local User Interface (LUI) if overwrite fails, (2) an IIO failure when a Held Job is deleted, and (3) an On Demand Image Overwrite failure when the overwrite is greater than 2 Gb.
|
2006-11-30
|
XEROX WorkCentre Products Held Job Deletion IIO Error Message
|
|
31815
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 have unknown impact and attack vectors, related to (1) an Immediate Image Overwrite (IIO) error message at the Local User Interface (LUI) if overwrite fails, (2) an IIO failure when a Held Job is deleted, and (3) an On Demand Image Overwrite failure when the overwrite is greater than 2 Gb.
|
2006-11-30
|
XEROX WorkCentre Products Unspecified On Demand Image Overwrite Failure
|
|
31816
Description:
(Description Provided by CVE) : The httpd.conf file in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 configures port 443 to be always active, which has unknown impact and remote attack vectors.
|
2006-11-30
|
XEROX WorkCentre Products Port 443 Persistence Unspecified Issue
|
|
31817
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 use weak permissions for certain files, which allows unspecified file access.
|
2006-11-30
|
XEROX WorkCentre Products Unspecified File Permission Issue
|
|
31818
Description:
(Description Provided by CVE) : The SNMP Agent in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 returns no error for a non-writable object, which has unknown impact and attack vectors. NOTE: due to the vagueness of the advisory, it is not clear whether this is a vulnerability, or a bug in a security feature.
|
2006-11-30
|
XEROX WorkCentre Products SNMP Agent Non-writable Object Error Code Unspecified Issue
|
|
31819
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not block the postgres port (5432/tcp), which has unknown impact and remote attack vectors, probably related to unauthorized connections to a PostgreSQL daemon.
|
2006-11-30
|
XEROX WorkCentre Products PostgreSQL Port Access Unspecified Issue
|
|
31820
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not check the Fully Qualified Domain Name (FQDN) during a "Validate Repository SSL Certificate" scan, which has unknown impact and attack vectors, possibly related to spoofed certificates.
|
2006-11-30
|
XEROX WorkCentre Products Validate Repository SSL Certificate FQDN Validation Weakness
|
|
31821
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not properly restrict access to SMB file resources, which allows remote attackers to gain unspecified file or directory access via vectors related to (1) visibility of the SMB "Homes" share and (2) SMB file system browsing.
|
2006-11-30
|
XEROX WorkCentre Products SMB Homes Share Disclosure
|
|
31822
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not properly restrict access to SMB file resources, which allows remote attackers to gain unspecified file or directory access via vectors related to (1) visibility of the SMB "Homes" share and (2) SMB file system browsing.
|
2006-11-30
|
XEROX WorkCentre Products Unspecified SMB File System Browsing
|
|
31823
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows local users to bypass security controls and boot Alchemy via certain alternate boot media, as demonstrated by a USB thumb drive.
|
2006-11-30
|
XEROX WorkCentre Products USB Alchemy Boot Bypass
|
|
31824
Description:
(Description Provided by CVE) : Multple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allow remote attackers to have an unspecified impact via unspecified vectors relating to "HTTP Security issues."
|
2006-11-30
|
XEROX WorkCentre Products Unspecified HTTP Security Issue
|
|
31825
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to download the audit log and obtain potentially sensitive information via unspecified vectors.
|
2006-11-30
|
XEROX WorkCentre Products Unauthenticated Audit Log Retrieval
|
|
31826
Description:
(Description Provided by CVE) : Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 leaves sensitive user data in http.log after an Immediate Image Overwrite (IIO), which allows local users to obtain the data by reading the http.log file.
|
2006-11-30
|
XEROX WorkCentre Products IIO http.log Information Disclosure
|
|
31827
Description:
(Description Provided by CVE) : ops3-dmn in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows attackers to cause a denial of service (application crash and core dump) via a certain PS file.
|
2006-11-30
|
XEROX WorkCentre Products Attached PS Script ops3-dmn DoS
|
|
31828
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to inject arbitrary web script or HTML via HTTP TRACE messages.
|
2006-11-30
|
XEROX WorkCentre Products Network Controller TRACE Method XSS
|
|
31829
Description:
(Description Provided by CVE) : The SNMP implementation in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 does not generate authentication failure traps, which allows remote attackers to more easily gain system access and obtain sensitive information via a brute force attack.
|
2006-11-30
|
XEROX WorkCentre Products SNMP Authentication Trap Failure
|
|
31513
Description:
(Description Provided by CVE) : Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pathname in an M3U file.
|
2006-11-30
|
AtomixMP3 M3U/PLS Playlist Pathname Parsing Overflow
|
|
31710
Description:
(Description Provided by CVE) : Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file, aka an "M3U UNC Name" attack.
|
2006-11-30
|
VUPlayer M3U/PLS Playlist Parsing Overflow
|
|
31701
Description:
(Description Provided by CVE) : Integer overflow in the KPresenter import filter for Microsoft PowerPoint files (filters/olefilters/lib/klaola.cc) in KOffice before 1.6.1 allows user-assisted remote attackers to execute arbitrary code via a crafted PPT file, which results in a heap-based buffer overflow.
|
2006-11-30
|
KOffice KPresenter Filter PowerPoint File Handling Overflow
|
|
31706
Description:
(Description Provided by CVE) : index.php in @lex Guestbook 4.0.1 allows remote attackers to obtain sensitive information via a skin parameter referencing a nonexistent skin, which reveals the installation path in an error message.
|
2006-11-30
|
@lex Guestbook index.php skin Variable Path Disclosure
|
|
31700
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Chama Cargo 4.36 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2006-11-30
|
Chama Cargo Unspecified XSS
|
|
34022
Description:
(Description Provided by CVE) : IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.
|
2006-11-30
|
IBM DB2 DB2ENGN.DLL Crafted SQLJRA Packet Remote DoS
|
|
31727
Description:
(Description Provided by CVE) : HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.
|
2006-11-30
|
Sun Java System Server Products HTTP Request Smuggling
|
|
31782
Description:
Unknown / Incomplete
|
2006-11-30
|
tnftpd Globbing Remote Overflow
|