| OSVDB ID | Disclosure Date | Title |
|
31467
Description:
(Description Provided by CVE) : The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has unknown attack vectors and results in a system crash.
|
2006-12-19
|
Linux kernel isdn_ppp_ccp_reset_alloc_state init_timer DoS
|
|
31526
Description:
cwmVote contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'archive.php' script not properly sanitizing user input supplied to the 'abs' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2006-12-19
|
cwmVote archive.php abs Parameter Remote File Inclusion
|
|
31589
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to inject arbitrary web script or HTML via the catname parameter.
|
2006-12-19
|
Mini Web Shop viewcategory.php catname XSS
|
|
31590
Description:
(Description Provided by CVE) : modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant from a more serious issue such as directory traversal.
|
2006-12-19
|
Mini Web Shop viewcategory.php catname Path Disclosure
|
|
32341
Description:
MailEnable is prone to an overflow condition. The POP service fails to properly sanitize user-supplied input to the PASS command, resulting in a stack-based buffer overflow. With a specially crafted request, a remote attacker can execute arbitrary code.
|
2006-12-18
|
MailEnable POP Service PASS Command Overflow
|
|
70606
Description:
PHP contains a flaw related to the accepting of the \0 character in a pathname. This may allow a context-dependent attacker to bypass access restrictions by combining this character with a safe file extension, such as .php\0.jpg.
|
2006-12-18
|
PHP Pathname \0 Character file_exists Function Access Restriction Bypass
|
|
32337
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the program specified in the post_change configuration line.
|
2006-12-18
|
chetcpasswd External Program Unspecified Privilege Escalation
|
|
30967
Description:
(Description Provided by CVE) : The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename.
|
2006-12-18
|
netrik textarea Form Field Arbitrary Command Execution
|
|
32130
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, which do not use the check_plain function.
|
2006-12-18
|
Drupal Project / Project Issue Tracking Module Unspecified XSS
|
|
32354
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in admin/index_sitios.php in Azucar CMS 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _VIEW parameter.
|
2006-12-18
|
Azucar admin/index_sitios.php CMS _VIEW Parameter Remote File Inclusion
|
|
32129
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote attackers to inject arbitrary web script or HTML via the Title field when editing a page. NOTE: some details were obtained from third party information.
|
2006-12-18
|
Drupal MySite Module Title Field XSS
|
|
32351
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to execute arbitrary PHP code via a URL in the q parameter.
|
2006-12-18
|
VerliAdmin index.php q Parameter Remote File Inclusion
|
|
31466
Description:
(Description Provided by CVE) : The do_coredump function in fs/exec.c in the Linux kernel 2.6.19 sets the flag variable to O_EXCL but does not use it, which allows context-dependent attackers to modify arbitrary files via a rewrite attack during a core dump.
|
2006-12-18
|
Linux Kernel fs/exec.c do_coredump() Function File Overwrite
|
|
31375
Description:
(Description Provided by CVE) : Multiple buffer overflows in the cmtp_recv_interopmsg function in the Bluetooth driver (net/bluetooth/cmtp/capi.c) in the Linux kernel 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.18.6, and 2.6.19.x, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via CAPI messages with a large value for the length of the (1) manu (manufacturer) or (2) serial (serial number) field.
|
2006-12-18
|
Linux Kernel Bluetooth CAPI Messages Overflow
|
|
32338
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the program specified in the post_change configuration line.
|
2006-12-18
|
chetcpasswd post_change Config Line Unspecified Privilege Escalation
|
|
31527
Description:
(Description Provided by CVE) : The eyeHome function in apps/eyeHome.eyeapp/aplic.php in EyeOS before 0.9.3-3 allows remote attackers to upload and execute arbitrary code via dangerous file extensions that are not all lowercase, which bypasses a cleansing operation.
|
2006-12-18
|
eyeOS aplic.php Arbitrary File Upload
|
|
32347
Description:
(Description Provided by CVE) : FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode with SSL enabled, allows remote attackers to cause a denial of service (refused connections) via malformed requests, which results in a mishandled exception.
|
2006-12-18
|
Mandiant First Response (MFR) FRAgent.exe Remote DoS
|
|
32348
Description:
(Description Provided by CVE) : FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces), opens sockets in non-exclusive mode, which allows local users to hijack the socket, and capture data or cause a denial of service (loss of daemon operation).
|
2006-12-18
|
Mandiant First Response (MFR) FRAgent.exe Socket Hijacking
|
|
32349
Description:
(Description Provided by CVE) : FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and configured to use only HTTP, allows local users to modify requests and responses between a client and an agent by hijacking an HTTP FRAgent daemon and conducting a man-in-the-middle (MITM) attack.
|
2006-12-18
|
Mandiant First Response (MFR) FRAgent.exe HTTP FRAgent Daemon MITM
|
|
32755
Description:
(Description Provided by CVE) : The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (application crash) via a malicious FTP server with a large number of blank 220 responses to the SYST command.
|
2006-12-18
|
GNU wget ftp-basic.c ftp_syst Function SYST Command Remote DoS
|
|
32072
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtoscript parameter.
|
2006-12-18
|
RateMe main.inc.php pathtoscript Parameter Remote File Inclusion
|
|
32343
Description:
(Description Provided by CVE) : The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX.
|
2006-12-18
|
NeoScale Systems CryptoStor 700 Series Smartcard Authentication Bypass
|
|
35837
Description:
(Description Provided by CVE) : SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote attackers to execute arbitrary SQL commands via the id_user parameter.
|
2006-12-18
|
uploader&downloader administration/administre2.php id_user SQL
|
|
58707
Description:
Apache WSS4J contains a flaw that may lead to an unauthorized bypass of credentials. The issue is triggered from UsernameTokenProcessor.java where the digest is checked and will validate any password value resulting in a loss of integrity.
|
2006-12-18
|
Apache WSS4J Crafted PasswordDigest Request Authentication Bypass
|
|
39210
Description:
(Description Provided by CVE) : SQL injection vulnerability in giris_yap.asp in Hazir Site 2.0 allows remote attackers to bypass authentication via the (1) k_a class or (2) sifre parameter.
|
2006-12-17
|
HazirSite giris_yap.asp Multiple Login Field SQL Injection
|
|
32350
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence.
|
2006-12-17
|
HyperVM display.php frm_action Parameter XSS
|
|
32344
Description:
(Description Provided by CVE) : The server component in Marathon Aleph One before 0.17.1 and 2006-12-17 allows remote attackers to cause a denial of service (application crash) via unspecified vectors related to "gathering net games."
|
2006-12-17
|
Marathon Aleph One Server Component Unspecified Remote DoS
|
|
32345
Description:
(Description Provided by CVE) : Format string vulnerability in Marathon Aleph One before 0.17.1 and 2006-12-17 might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the TopLevelLogger::logMessageV function in Misc/Logging.cpp. NOTE: some details were obtained from third party information.
|
2006-12-17
|
Marathon Aleph One Misc/Logging.cpp TopLevelLogger::logMessageV Function Format String
|
|
32334
Description:
(Description Provided by CVE) : Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RETR commands with long arguments.
|
2006-12-17
|
Star FTP Server Crafted RETR Commands DoS
|
|
37366
Description:
(Description Provided by CVE) : The Allied Telesis AT-9000/24 Ethernet switch has a default password for its admin account, "manager," which allows remote attackers to perform unauthorized actions.
|
2006-12-16
|
Allied Telesis AT-9000/24 Default Admin Account Password
|
|
32501
Description:
(Description Provided by CVE) : The Allied Telesis AT-9000/24 Ethernet switch accepts management packets from arbitrary VLANs, contrary to the documentation, which allows remote attackers to conduct attacks against the switch from unexpected locations.
|
2006-12-16
|
Allied Telesis AT-9000/24 Management Interface VLAN Restriction Bypass
|
|
31232
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-12-16
|
MxBB Portal mx_meeting Module meeting_constants.php module_root_path Parameter Remote File Inclusion
|
|
31233
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-12-16
|
MxBB Portal mx_charts Module charts_constants.php module_root_path Parameter Remote File Inclusion
|
|
39215
Description:
Unknown / Incomplete
|
2006-12-16
|
Sun Java API Class java.util.Random Number Generation Prediction Weakness
|
|
36831
Description:
@Mail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not sanitize incoming emails while rendering HTML emails. This could allow a user to create a specially crafted email that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-12-16
|
@Mail Global.pm Crafted Email XSS
|
|
32067
Description:
(Description Provided by CVE) : SQL injection vulnerability in haber.asp in Contra Haber Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2006-12-16
|
Contra Haber Sistemi haber.asp id Parameter SQL Injection
|
|
33278
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.asp and the (2) company and (3) username fields on (b) the web login page. NOTE: some details were obtained from third party information.
|
2006-12-16
|
SiteCatalyst search.asp ss Parameter XSS
|
|
33280
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.asp and the (2) company and (3) username fields on (b) the web login page. NOTE: some details were obtained from third party information.
|
2006-12-16
|
SiteCatalyst Login Page Multiple Parameter XSS
|
|
35719
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.
|
2006-12-16
|
Web Links lang_admin.php mx_root_path Parameter Remote File Inclusion
|
|
32355
Description:
(Description Provided by CVE) : Unspecified vulnerability in Nortel CallPilot 4.x Server has unknown impact and attack vectors, aka P-2006-0011-GLOBAL.
|
2006-12-15
|
Nortel CallPilot Server Unspecified Issue
|