| OSVDB ID | Disclosure Date | Title |
|
38981
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activation.php3 and (2) my.logon.php3.
|
2007-11-30
|
F5 FirePass 4100 SSL VPN my.logon.php3 URL XSS
|
|
42984
Description:
(Description Provided by CVE) : QEMU 0.9.0 allows local users of a Windows XP SP2 guest operating system to overwrite the TranslationBlock (code_gen_buffer) buffer, and probably have unspecified other impacts related to an "overflow," via certain Windows executable programs, as demonstrated by qemu-dos.com.
|
2007-11-30
|
QEMU TranslationBlock (code_gen_buffer) Buffer Overwrite Local DoS
|
|
82806
Description:
ESP-PIX contains a flaw that is triggered when supplying the same tags and words for multiple posts. This may allow an attacker to bypass CAPTCHA tests.
|
2007-11-30
|
ESP-PIX Tag / Word Replay CAPTCHA Bypass
|
|
38934
Description:
Unknown / Incomplete
|
2007-11-30
|
Hitachi JP1/Cm2/Network Node Manager Unspecified XSS
|
|
38935
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2007-11-30
|
HP OpenView Network Node Manager (OV NNM) Unspecified XSS
|
|
39715
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to cause a denial of service (browser crash) via a long argument to the c method.
|
2007-11-30
|
Yahoo! Toolbar yt.ythelper.2 Helper Class ActiveX c Method Remote DoS
|
|
40549
Description:
(Description Provided by CVE) : Unspecified vulnerability in OpenOffice.org code in Planamesa NeoOffice 2.2.2 before Patch 4 has unknown impact and attack vectors related to MacOS 10.3.9 .odb files. NOTE: it is not clear whether this issue is a vulnerability.
|
2007-11-30
|
NeoOffice OpenOffice.org Code odb Handling Unspecified Issue
|
|
44312
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) install_module.php and (b) uninstall_module.php in upload/xax/admin/modules/, (c) upload/xax/admin/patch/index.php, and (d) install_module.php and (e) uninstall_module.php in upload/xax/ossigeno/admin/; and the (2) ossigeno parameter to (f) ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php, different vectors than CVE-2007-5234.
|
2007-11-30
|
Ossigeno CMS upload/xax/admin/modules/install_module.php level Parameter Remote File Inclusion
|
|
44313
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) install_module.php and (b) uninstall_module.php in upload/xax/admin/modules/, (c) upload/xax/admin/patch/index.php, and (d) install_module.php and (e) uninstall_module.php in upload/xax/ossigeno/admin/; and the (2) ossigeno parameter to (f) ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php, different vectors than CVE-2007-5234.
|
2007-11-30
|
Ossigeno CMS upload/xax/admin/modules/uninstall_module.php level Parameter Remote File Inclusion
|
|
44314
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) install_module.php and (b) uninstall_module.php in upload/xax/admin/modules/, (c) upload/xax/admin/patch/index.php, and (d) install_module.php and (e) uninstall_module.php in upload/xax/ossigeno/admin/; and the (2) ossigeno parameter to (f) ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php, different vectors than CVE-2007-5234.
|
2007-11-30
|
Ossigeno CMS upload/xax/admin/patch/index.php level Parameter Remote File Inclusion
|
|
44315
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) install_module.php and (b) uninstall_module.php in upload/xax/admin/modules/, (c) upload/xax/admin/patch/index.php, and (d) install_module.php and (e) uninstall_module.php in upload/xax/ossigeno/admin/; and the (2) ossigeno parameter to (f) ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php, different vectors than CVE-2007-5234.
|
2007-11-30
|
Ossigeno CMS upload/xax/ossigeno/admin/install_module.php level Parameter Remote File Inclusion
|
|
44316
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) install_module.php and (b) uninstall_module.php in upload/xax/admin/modules/, (c) upload/xax/admin/patch/index.php, and (d) install_module.php and (e) uninstall_module.php in upload/xax/ossigeno/admin/; and the (2) ossigeno parameter to (f) ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php, different vectors than CVE-2007-5234.
|
2007-11-30
|
Ossigeno CMS upload/xax/ossigeno/admin/uninstall_module.php level Parameter Remote File Inclusion
|
|
44317
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) install_module.php and (b) uninstall_module.php in upload/xax/admin/modules/, (c) upload/xax/admin/patch/index.php, and (d) install_module.php and (e) uninstall_module.php in upload/xax/ossigeno/admin/; and the (2) ossigeno parameter to (f) ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php, different vectors than CVE-2007-5234.
|
2007-11-30
|
Ossigeno CMS ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php ossigeno Parameter Remote File Inclusion
|
|
39600
Description:
(Description Provided by CVE) : The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that rely on secrecy of those values.
|
2007-11-29
|
FreeBSD sys_dev_random Random Data Disclosure Security Bypass
|
|
38940
Description:
(Description Provided by CVE) : The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than expected and makes it easier for attackers to bypass protection mechanisms that rely on the randomness.
|
2007-11-29
|
OpenSSL FIPS Object Module PRNG Weakness
|
|
42455
Description:
(Description Provided by CVE) : index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.
|
2007-11-29
|
FTP Admin index.php loggedin Variable Authentication Bypass
|
|
42456
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.
|
2007-11-29
|
FTP Admin index.php page Parameter Traversal Local File Inclusion
|
|
42457
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action.
|
2007-11-29
|
FTP Admin index.php error Variable Error Page Action XSS
|
|
43283
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wpcf_email, (2) wpcf_subject, (3) wpcf_question, (4) wpcf_answer, (5) wpcf_success_msg, (6) wpcf_error_msg, or (7) wpcf_msg parameter to wp-admin/admin.php, or (8) the SRC attribute of an IFRAME element.
|
2007-11-29
|
WP-ContactForm Plugin for WordPress wp-admin/admin.php Multiple Parameter XSS
|
|
43284
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wpcf_email, (2) wpcf_subject, (3) wpcf_question, (4) wpcf_answer, (5) wpcf_success_msg, (6) wpcf_error_msg, or (7) wpcf_msg parameter to wp-admin/admin.php, or (8) the SRC attribute of an IFRAME element.
|
2007-11-29
|
WP-ContactForm Plugin for WordPress wp-admin/admin.php IFRAME Element SRC Attribute XSS
|
|
82763
Description:
WP-ContactForm Plugin for WordPress contains a flaw that may allow an attacker to bypass the anti-automated CAPTCHA test. This flaw is triggered when an attacker supplies the same value for the 'wpcf_response' parameter on multiple pages allowing an attacker to bypass CAPTCHA testing.
|
2007-11-29
|
WP-ContactForm Plugin for WordPress wpcf_response Parameter Replay CAPTCHA Bypass
|
|
40827
Description:
(Description Provided by CVE) : Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some programs that access hardware resources, as demonstrated by the (1) cfgadm and (2) format programs.
|
2007-11-29
|
Solaris fcp / devfs cfgadm Local Race Condition DoS
|
|
40826
Description:
(Description Provided by CVE) : Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some programs that access hardware resources, as demonstrated by the (1) cfgadm and (2) format programs.
|
2007-11-29
|
Solaris fcp / devfs format Local Race Condition DoS
|
|
40548
Description:
(Description Provided by CVE) : HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods."
|
2007-11-29
|
OpenOffice.org (OOo) HSQLDB Database Document Handling Unspecified Arbitrary Java Code Execution
|
|
43282
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php.
|
2007-11-29
|
WP-ContactForm Plugin for WordPress wp-admin/admin.php Multiple Parameter CSRF
|
|
42454
Description:
(Description Provided by CVE) : TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-11-29
|
TuMusika Evolution phpinfo.php Remote Information Disclosure
|
|
42809
Description:
(Description Provided by CVE) : uploadimg.php in the Automatic Image Upload with Thumbnails (imgUpload) module 1.3.2 for PunBB only verifies the Content-type field of uploaded files, which allows remote attackers to upload and execute arbitrary content via a file with a (1) JPG, (2) GIF, or (3) PNG MIME type.
|
2007-11-29
|
Automatic Image Upload with Thumbnails (imgUpload) Module for PunBB uploadimg.php Crafted MIME Type Unrestricted File Upload
|
|
44153
Description:
(Description Provided by CVE) : Memory leak in the Red Hat Content Accelerator kernel patch in Red Hat Enterprise Linux (RHEL) 4 and 5 allows local users to cause a denial of service (memory consumption) via a large number of open requests involving O_ATOMICLOOKUP.
|
2007-11-29
|
Red Hat Linux Content Accelerator Patch for Linux Kernel O_ATOMICLOOKUP Request Saturation Local DoS
|
|
38924
Description:
(Description Provided by CVE) : SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php.
|
2007-11-29
|
Seditio plug.php pag_sub[] Parameter SQL Injection
|
|
38932
Description:
(Description Provided by CVE) : SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL commands via (1) ANI and (2) DNIS arguments.
|
2007-11-29
|
Asterisk Call Detail Record Postgres Multiple Strings SQL Injection
|
|
38933
Description:
(Description Provided by CVE) : SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
2007-11-29
|
Asterisk Postgres Realtime Engine SQL Injection
|
|
39697
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) roomNo and possibly the (2) bookid parameter.
|
2007-11-29
|
Web-MeetMe play.php Multiple Parameter Traversal Arbitrary File Access
|
|
39698
Description:
(Description Provided by CVE) : Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read arbitrary files via a .. (dot dot) in the sFilePath parameter. NOTE: exploitation requires that the product is configured, but has zero files in the database.
|
2007-11-29
|
LearnLoop include/file_download.php sFilePath Parameter Traversal Arbitrary File Access
|
|
39699
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) Root and (2) Path parameters.
|
2007-11-29
|
WebED mod/chat/index.php Multiple Parameter Traversal Arbitrary File Access
|
|
39700
Description:
(Description Provided by CVE) : Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer parameter.
|
2007-11-29
|
KML share region.php layer Parameter Traversal Arbitrary File Access
|
|
43715
Description:
(Description Provided by CVE) : Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demonstrated by kr.aiff.
|
2007-11-29
|
Microsoft Windows Media Player (WMP) AIFF File Handling DoS
|
|
44154
Description:
(Description Provided by CVE) : The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remote attackers to bypass authentication and obtain login access by making a login attempt while a different client is logged in, and then resubmitting the login attempt once the other client exits.
|
2007-11-29
|
APC Switched Rack PDU Race Condition Remote Authentication Bypass
|
|
74029
Description:
(Description Provided by CVE) : Open Ticket Request System (OTRS) before 2.2.6, when customer group support is enabled, allows remote authenticated users to bypass intended access restrictions and perform web-interface updates to tickets by leveraging queue read permissions.
|
2007-11-29
|
OTRS (Open Ticket Request System) Customer Group Support Queue Read Permissions Remote Access Restriction Bypass
|
|
43316
Description:
Unknown / Incomplete
|
2007-11-28
|
Netscape Navigator window.location HTTP Referer Header CSRF
|
|
43317
Description:
Unknown / Incomplete
|
2007-11-28
|
Netscape Navigator Multiple Unspecified Memory Corruption
|