| OSVDB ID | Disclosure Date | Title |
|
38694
Description:
(Description Provided by CVE) : libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
|
2007-09-27
|
Pidgin libpurple MSN nudge Message Remote DoS
|
|
37504
Description:
(Description Provided by CVE) : Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow remote attackers to send packets to an interface for which network exposure was unintended.
|
2007-09-27
|
Cisco Catalyst 6500 / 7600 Series EOBC Local Interface Weakness
|
|
37712
Description:
(Description Provided by CVE) : Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors related to "the handling of thread contexts."
|
2007-09-27
|
Solaris Kernel Thread Context Handling Local DoS
|
|
37757
Description:
(Description Provided by CVE) : Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 8.x container, allows remote attackers to execute arbitrary code via unspecified vectors.
|
2007-09-27
|
Sun Java System Access Manager Unspecified Remote Code Execution
|
|
37758
Description:
(Description Provided by CVE) : Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.
|
2007-09-27
|
Sun Java System Access Manager Container Restart Authentication Bypass
|
|
41377
Description:
(Description Provided by CVE) : F-Secure Anti-Virus for Windows Servers 7.0 64-bit edition allows local users to bypass virus scanning by using the system32 directory to store a crafted (1) archive or (2) packed executable. NOTE: in many environments, this does not cross privilege boundaries because any process able to write to system32 could also shut off F-Secure Anti-Virus.
|
2007-09-27
|
F-Secure Anti-Virus for Windows system32 Directory Crafted File Detection Bypass
|
|
41363
Description:
A buffer overflow exists in HSM. The CsAgent service fails to validate certain opcodes resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-09-27
|
BrightStor Hierarchical Storage Manager (HSM) Unspecified CsAgent Service Command Crafted Opcode Multiple Remote Overflows
|
|
41364
Description:
(Description Provided by CVE) : Multiple integer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary code via unspecified CsAgent service commands that trigger a heap-based buffer overflow.
|
2007-09-27
|
BrightStor Hierarchical Storage Manager (HSM) Unspecified CsAgent Service Command Remote Overflow
|
|
37370
Description:
Nederland contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'includes/archive/archive_topic.php' not properly sanitizing user input supplied to the 'phpbb_root_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2007-09-27
|
Nederland(s) includes/archive/archive_topic.php phpbb_root_path Parameter Remote File Inclusion
|
|
37965
Description:
Newswriter contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'editfunc.inc.php' script not properly sanitizing user input supplied to the 'NWCONF_SYSTEM[server_path]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-09-27
|
Newswriter editfunc.inc.php NWCONF_SYSTEM[server_path] Parameter Remote File Inclusion
|
|
38883
Description:
Chupix CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'admin/include/header.php' script not properly sanitizing user input supplied to the 'repertoire' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-09-27
|
Chupix CMS admin/include/header.php repertoire Parameter Remote File Inclusion
|
|
39626
Description:
lustig.cms contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'forum/forum.php' not properly sanitizing user input supplied to the 'view' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2007-09-27
|
lustig.cms forum/forum.php view Parameter Remote File Inclusion
|
|
39630
Description:
SiteX CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'search.php' script not properly sanitizing user-supplied input to the 'search' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-09-27
|
SiteX CMS search.php search Parameter SQL Injection
|
|
39633
Description:
Novus contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'p' variables upon submission to the 'buscar.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-09-27
|
Novus buscar.asp p Parameter XSS
|
|
39643
Description:
phpFidoNode contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'phfito-post.php' script not properly sanitizing user input supplied to the 'SRC_PATH' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-09-27
|
phpFidoNode phfito-post.php SRC_PATH Parameter Remote File Inclusion
|
|
50706
Description:
Unknown / Incomplete
|
2007-09-27
|
Promise NAS NS4300N Web GUI usercp.php user Parameter Arbitrary Account Password Manipulation
|
|
51208
Description:
Unknown / Incomplete
|
2007-09-27
|
SiteX CMS FCKEditor upload.php Arbitrary File Upload
|
|
87466
Description:
MySQL contains a flaw that is due to the application not properly revoking SSL certificates once they've been authenticated. This may allow a remote attacker to more easily compromise a user's system.
|
2007-09-27
|
MySQL SSL Certificate Revocation Weakness
|
|
90273
Description:
libpixman contains a flaw in the create_bits function of pixman-image.c that may allow a denial of service. The issue is triggered when writing to a PNG image file. With a specially crafted file, a context-dependent attacker can cause an integer overflow. This will result in a loss of availability for the program.
|
2007-09-27
|
libpixman pixman-image.c create_bits Function PNG Image Writing Integer Overflow DoS
|
|
41013
Description:
(Description Provided by CVE) : Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root.
|
2007-09-26
|
IBM DB2 Universal Database SSL LOAD GSKIT Action Unspecified Issue
|
|
40614
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web script or HTML via (1) the l_username parameter to the default URI under admin/ or (2) the l_emoticonlist parameter to admin/emoticonlist.php.
|
2007-09-26
|
SimpGB admin/ Default URI l_username Parameter XSS
|
|
40615
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web script or HTML via (1) the l_username parameter to the default URI under admin/ or (2) the l_emoticonlist parameter to admin/emoticonlist.php.
|
2007-09-26
|
SimpGB admin/emoticonlist.php l_emoticonlist Parameter XSS
|
|
37328
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/login.php and (2) includes/lang/language.php, different vectors than CVE-2007-4279.
|
2007-09-26
|
FrontAccounting (FA) access/login.php path_to_root Parameter Remote File Inclusion
|
|
37329
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/login.php and (2) includes/lang/language.php, different vectors than CVE-2007-4279.
|
2007-09-26
|
FrontAccounting (FA) includes/lang/language.php path_to_root Parameter Remote File Inclusion
|
|
51173
Description:
Unknown / Incomplete
|
2007-09-26
|
Joomla! includes/ Multiple Script Direct Request Path Disclosure
|
|
37344
Description:
(Description Provided by CVE) : SQL injection vulnerability in notas.asp in Novus 1.0 allows remote attackers to execute arbitrary SQL commands via the nota_id parameter.
|
2007-09-26
|
Novus notas.asp nota_id Parameter SQL Injection
|
|
39623
Description:
SoftBiz Classifieds contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'store_info.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-09-26
|
SoftBiz Classifieds store_info.php id Parameter SQL Injection
|
|
39624
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parameter in a browse action. NOTE: it was separately reported that ActiveKB 1.5 is also affected.
|
2007-09-26
|
Interspire ActiveKB NX index.php browse Action catId Parameter SQL Injection
|
|
43674
Description:
(Description Provided by CVE) : The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.
|
2007-09-26
|
PHP disable_functions Feature Alias Security Bypass
|
|
50463
Description:
(Description Provided by CVE) : SQL injection vulnerability in Wiz-Ad 1.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-09-26
|
Wiz-Ad Unspecified SQL Injection
|
|
45521
Description:
(Description Provided by CVE) : Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png.
|
2007-09-25
|
Microsoft Windows Explorer (explorer.exe) Malformed PNG Handling Remote DoS
|
|
50781
Description:
Black Lily contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the products.php script not properly sanitizing user-supplied input to the class parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-09-25
|
Black Lily products.php class Parameter SQL Injection
|
|
45479
Description:
(Description Provided by CVE) : SimpNews 2.41.03 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc.
|
2007-09-25
|
SimpNews .inc File Direct Request Information Disclosure
|
|
37361
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web script or HTML via the cat_data[color] parameter to (1) preferences/inc/class.uicategories.inc.php and (2) admin/inc/class.uicategories.inc.php.
|
2007-09-25
|
eGroupWare preferences/inc/class.uicategories.inc.php cat_data[color] Parameter XSS
|
|
37362
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web script or HTML via the cat_data[color] parameter to (1) preferences/inc/class.uicategories.inc.php and (2) admin/inc/class.uicategories.inc.php.
|
2007-09-25
|
eGroupWare admin/inc/class.uicategories.inc.php cat_data[color] Parameter XSS
|
|
37334
Description:
(Description Provided by CVE) : Unspecified vulnerability in the HID (Human Interface Device) class driver in Sun Solaris 8, 9, and 10 before 20070925 allows local users to cause a denial of service (panic) via unspecified vectors.
|
2007-09-25
|
Solaris Human Interface Device (HID) Unspecified Local DoS
|
|
38529
Description:
(Description Provided by CVE) : Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to "alter or access" HTTPS content via an HTTP session with a crafted web page that causes Javascript to be applied to HTTPS pages from the same domain.
|
2007-09-25
|
Apple Safari on iPhone Cross-SSL HTTP Content Manipulation
|
|
38530
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1 allows remote attackers to inject arbitrary web script or HTML by causing Javascript events to be applied to a frame in another domain.
|
2007-09-25
|
Apple Safari on iPhone Cross-domain Frame XSS
|
|
38531
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to inject arbitrary web script or HTML via frame tags.
|
2007-09-25
|
Apple Safari on iPhone Frame Tag XSS
|
|
38532
Description:
(Description Provided by CVE) : Safari in Apple iPhone 1.1.1, when requested to disable Javascript, does not disable it until Safari is restarted, which might leave Safari open to attacks that the user does not expect.
|
2007-09-25
|
Apple Safari on iPhone JavaScript Functionality Persistence
|