| OSVDB ID | Disclosure Date | Title |
|
37853
Description:
(Description Provided by CVE) : Unspecified vulnerability in Hitachi JP1/Cm2/Hierarchical Viewer (HV) 06-00 through 06-71-/B allows remote attackers to cause a denial of service (application stop and web interface outage) via certain "unexpected data."
|
2007-07-31
|
Hitachi JP1/Cm2/Hierarchical Viewer (HV) Unspecified Remote DoS
|
|
37852
Description:
uCosminexus Application Server contains an unspecified flaw that may allow a user to use the session data of another user. It is possible that the flaw may allow remote authenticated users to access or modify another user's data resulting in a loss of integrity.
|
2007-07-31
|
Hitachi Multiple Products Cosminexus Component Container Session Data Handling Privilege Escalation
|
|
46972
Description:
(Description Provided by CVE) : The Groupmax Scheduler_Facilities management tool in Hitachi Groupmax Groupware Server 07-00-/F through 07-32-/A before 20070731 does not properly manage schedule server configuration data, which might allow attackers to obtain sensitive information via unspecified vectors.
|
2007-07-31
|
Hitache Groupmax Groupware Server Scheduler_Facilities Management Tool Unspecified Configuration Data Disclosure
|
|
36963
Description:
A buffer overflow exists in Mac OS X. iChat fails to validate UPnP IGD packets resulting in a buffer overflow. With a specially crafted packet, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-07-31
|
Apple Mac OS X iChat UPnP IGD Crafted Packet Overflow
|
|
36964
Description:
A heap overflow exists in Mac OS X. The CoreAudio Java interface fails to validate applets resulting in a heap overflow. With a specially crafted applet, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-07-31
|
Apple Mac OS X CoreAudio Java Interface Crafted Applet Arbitrary Code Execution
|
|
36965
Description:
A heap overflow exists in Mac OS X. The CoreAudio Java interface fails to validate applets resulting in a heap overflow. With a specially crafted applet, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-07-31
|
Apple Mac OS X CoreAudio Java Interface Crafted Applet Remote Command Execution
|
|
36966
Description:
Mac OS X contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when by a design flaw in the CoreAudio Java interface, which may allow an attacker to free arbitrary memory. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2007-07-31
|
Apple Mac OS X CoreAudio Java Interface JDirect Arbitrary Code Execution
|
|
36967
Description:
A buffer overflow exists in Mac OS X. The mDNS Responder fails to validate UPnP IGD packets resulting in a buffer overflow. With a specially crafted packet, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-07-31
|
Apple Mac OS X mDNSResponder UPnP IGD Crafted Packet Remote Overflow
|
|
36968
Description:
Mac OS X contains a flaw related to the handling of global objects in Safari that may allow an attacker to perform a cross-site scripting attack with a maliciously crafted web page. No further details have been provided.
|
2007-07-31
|
Apple Mac OS X WebCore Global Object Persistence XSS
|
|
36969
Description:
Mac OS X contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a user is enticed to visit a maliciously crafted web page which uses a pop-up window to read the contents of another window, which will disclose the contents of other web pages resulting in a loss of confidentiality.
|
2007-07-31
|
Apple Mac OS X WebCore Popup Cross-Domain Information Disclosure
|
|
36970
Description:
(Description Provided by CVE) : WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page.
|
2007-07-31
|
Apple Safari WebKit Crafted Web Page Arbitrary Java Applet Execution
|
|
36971
Description:
Mac OS X contains a flaw that may allow a user to exceed disk quota levels. The issue is triggered when the Samba process improperly drops privileges. This flaw may lead to a loss of integrity.
|
2007-07-31
|
Apple Mac OS X Samba Server Disk Quota Bypass
|
|
36972
Description:
A memory corruption flaw exists in Mac OS X. Quartz Composer fails to validate files resulting in a access to an uninitialized object pointer. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-07-31
|
Apple Mac OS X Quartz Composer Crafted File Arbitrary Command Execution
|
|
36973
Description:
An overflow exists in Mac OS X. Preview fails to validate PDF files resulting in an integer overflow. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-07-31
|
Apple Mac OS X PDFKit Preview PDF File Handling Overflow
|
|
36974
Description:
Mac OS X contains a flaw related to the the parsing of HTTP responses in CFNetwork that may allow a remote attacker to perform a cross-site scripting attack. No further details have been provided.
|
2007-07-31
|
Apple Mac OS X CFNetwork Unspecified CRLF Injection
|
|
36975
Description:
Mac OS X contains a flaw that may allow a context-dependent attacker to execute arbitrary ftp commands as the logged-in user. The issue is triggered when a user clicks on a maliciously crafted FTP URI. It is possible that the flaw may allow execution of commands on servers available to the logged-in user resulting in a loss of integrity.
|
2007-07-31
|
Apple Mac OS X CFNetwork ftp: URI Arbitrary FTP Command Execution
|
|
37560
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors. NOTE: this is probably different from CVE-2007-0916, but this is not certain due to lack of vendor details.
|
2007-07-31
|
HP-UX ARPA Transport Unspecified Local DoS
|
|
37561
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause an unspecified denial of service via unknown vectors.
|
2007-07-31
|
HP-UX ARPA Transport Unspecified Remote DoS
|
|
46994
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
|
2007-07-31
|
WordPress Admin Panel options.php Options Database Table XSS
|
|
46995
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
|
2007-07-31
|
WordPress Admin Panel link-import.php opml_url Parameter XSS
|
|
38298
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in (1) Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON Registration Authority Web Interface 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2007-07-31
|
RSA KEON Registration Authority Request-spk.xuda Unspecified Parameter XSS
|
|
38299
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in (1) Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON Registration Authority Web Interface 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2007-07-31
|
RSA KEON Registration Authority Add-msie-request.xuda Unspecified XSS
|
|
38987
Description:
(Description Provided by CVE) : Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
|
2007-07-31
|
Claroline inc/lib/language.lib.php language Parameter Traversal Local File Inclusion
|
|
39048
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the BlueSkychat (BlueSkyCat) ActiveX control (V2.V2Ctrl.1) in v2.ocx 8.1.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the second argument to the ConnecttoServer method.
|
2007-07-31
|
BlueSkyCat ActiveX v2.ocx (V2.V2Ctrl.1) ConnecttoServer Method Remote Overflow
|
|
39192
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.
|
2007-07-31
|
GMaps Component for Joomla! index.php viewmap Action mapId Parameter SQL Injection
|
|
39216
Description:
WebEvent contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'cmd' variable upon submission to the 'webevent.cgi' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-07-31
|
WebEvent webevent.cgi cmd Parameter XSS
|
|
39295
Description:
(Description Provided by CVE) : irc-channel.c in ngIRCd before 0.10.3 allows remote attackers to cause a denial of service (crash) via a JOIN command without a channel argument.
|
2007-07-31
|
ngIRCd irc-channel.c Null channel Argument JOIN Command Remote DoS
|
|
39371
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-general.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-07-31
|
Wordpress options-general.php page_options Parameter SQL Injection
|
|
39372
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-writing.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-07-31
|
Wordpress options-writing.php page_options Parameter SQL Injection
|
|
39373
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-reading.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-07-31
|
Wordpress options-reading.php page_options Parameter SQL Injection
|
|
39374
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-discussion.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-07-31
|
Wordpress options-discussion.php page_options Parameter SQL Injection
|
|
39375
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-privacy.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-07-31
|
Wordpress options-privacy.php page_options Parameter SQL Injection
|
|
39376
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-permalink.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-07-31
|
Wordpress options-permalink.php page_options Parameter SQL Injection
|
|
39377
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-misc.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-07-31
|
Wordpress options-misc.php page_options Parameter SQL Injection
|
|
48466
Description:
(Description Provided by CVE) : fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
|
2007-07-31
|
Linux Kernel dio Subsystem fs/direct-io.c Local DoS
|
|
39029
Description:
Unknown / Incomplete
|
2007-07-30
|
vBulletin Multiple Script Remote File Inclusion
|
|
39030
Description:
phpVoter contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'functions.inc.php' script not properly sanitizing user input supplied to the 'sitepath' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-07-30
|
phpVoter functions.inc.php sitepath Parameter Remote File Inclusion
|
|
39033
Description:
Unknown / Incomplete
|
2007-07-30
|
Phorm fileupload.php Arbitrary PHP File Upload
|
|
39369
Description:
(Description Provided by CVE) : Multiple buffer overflows in Konst CenterICQ 4.9.11 through 4.21 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this might overlap CVE-2007-0160.
|
2007-07-30
|
CenterICQ Multiple Unspecified Remote Overflows
|
|
51434
Description:
(Description Provided by CVE) : Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
|
2007-07-30
|
Vim src/ex_cmds.c helptags_one Function helptags Format String
|