| OSVDB ID | Disclosure Date | Title |
|
44479
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in the Siebel SimBuilder component in Oracle Siebel Enterprise 7.8.2 and 7.8.5 have unknown impact and remote or local attack vectors, aka (1) SEBL01, (2) SEBL02, (3) SEBL03, (4) SEBL04, (5) SEBL05, and (6) SEBL06.
|
2008-04-16
|
Oracle Siebel SimBuilder HTTP Unspecified Remote Information Disclosure
|
|
44480
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in the Siebel SimBuilder component in Oracle Siebel Enterprise 7.8.2 and 7.8.5 have unknown impact and remote or local attack vectors, aka (1) SEBL01, (2) SEBL02, (3) SEBL03, (4) SEBL04, (5) SEBL05, and (6) SEBL06.
|
2008-04-16
|
Oracle Siebel SimBuilder HTTP Unspecified Local Information Disclosure (SEBL05)
|
|
44481
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in the Siebel SimBuilder component in Oracle Siebel Enterprise 7.8.2 and 7.8.5 have unknown impact and remote or local attack vectors, aka (1) SEBL01, (2) SEBL02, (3) SEBL03, (4) SEBL04, (5) SEBL05, and (6) SEBL06.
|
2008-04-16
|
Oracle Siebel SimBuilder HTTP Unspecified Local Information Disclosure (SEBL06)
|
|
44483
Description:
(Description Provided by CVE) : Unspecified vulnerability in the PeopleSoft HCM Recruiting component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.8 SP1 has unknown impact and local attack vectors, aka PSE02.
|
2008-04-16
|
Oracle PeopleSoft HCM Recruiting HTTP Unspecified Remote Issue
|
|
44484
Description:
(Description Provided by CVE) : Unspecified vulnerability in the PeopleSoft HCM ePerformance component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9 and 9.0 has unknown impact and local attack vectors, aka PSE03.
|
2008-04-16
|
Oracle PeopleSoft HCM ePerformance HTTP Unspecified Remote Issue
|
|
44486
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.
|
2008-04-16
|
Oracle Advanced Pricing HTTP Unspecified Remote Information Disclosure (APP02)
|
|
44487
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.
|
2008-04-16
|
Oracle Advanced Pricing HTTP Unspecified Remote Issue (APP03)
|
|
44488
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.
|
2008-04-16
|
Oracle Application Object Library HTTP Unspecified Remote Issue (APP04)
|
|
44489
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka (1) APP01 and (2) APP10; and (b) Applications Framework, aka (3) APP05.
|
2008-04-16
|
Oracle Applications Framework HTTP Unspecified Remote Information Disclosure
|
|
44490
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.
|
2008-04-16
|
Oracle Applications Manager HTTP Unspecified Information Disclosure
|
|
44491
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.
|
2008-04-16
|
Oracle Application Object Library HTTP Unspecified Remote Issue (APP07)
|
|
44492
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.
|
2008-04-16
|
Oracle Applications Technology Stack HTTP Authenticated Unspecified Information Disclosure
|
|
44493
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.
|
2008-04-16
|
Oracle Advanced Pricing HTTP Authenticated Unspecified Remote Issue (APP09)
|
|
44494
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka (1) APP01 and (2) APP10; and (b) Applications Framework, aka (3) APP05.
|
2008-04-16
|
Oracle Advanced Pricing HTTP Authenticated Unspecified Remote Issue (APP10)
|
|
44495
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.
|
2008-04-16
|
Oracle Application Object Library HTTP Authenticated Unspecified Remote Issue
|
|
44497
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Dynamic Monitoring Service component in Oracle Application Server 9.0.4.3, 10.1.2.2, and 10.1.3.3 has unknown impact and remote attack vectors, aka AS02.
|
2008-04-16
|
Oracle Application Server Dynamic Monitoring Service HTTP Unspecified Remote Issue
|
|
44499
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 has unknown impact and remote attack vectors, aka AS03.
|
2008-04-16
|
Oracle Application Server Portal HTTP Unspecified Remote Issue
|
|
44501
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Application Express component in Oracle Application Express 3.0.1 has unknown impact and remote attack vectors, aka APEX02.
|
2008-04-16
|
Oracle Application Express HTTP Unspecified Remote Issue
|
|
44503
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote unauthenticated or authenticated attack vectors related to (1) SYS.DBMS_AQ in the Advanced Queuing component, aka DB01; (2) Core RDBMS, aka DB03; (3) SDO_GEOM in Oracle Spatial, aka DB06; (4) Export, aka DB12; and (5) DBMS_STATS in Query Optimizer, aka DB13. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB06 is SQL injection, and DB13 occurs when the OUTLN account is reset to use a hard-coded password.
|
2008-04-16
|
Oracle Database Advanced Queuing SYS.DBMS_AQ Unspecified Remote Issue
|
|
44505
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to DBMS_CDC_UTILITY, aka DB02. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that DB02 is for SQL injection in LOCK_CHANGE_SET.
|
2008-04-16
|
Oracle Database Change Data Capture SYS.DBMS_CDC_UTILITY.LOCK_CHANGE_SET SQL Injection
|
|
44506
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote unauthenticated or authenticated attack vectors related to (1) SYS.DBMS_AQ in the Advanced Queuing component, aka DB01; (2) Core RDBMS, aka DB03; (3) SDO_GEOM in Oracle Spatial, aka DB06; (4) Export, aka DB12; and (5) DBMS_STATS in Query Optimizer, aka DB13. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB06 is SQL injection, and DB13 occurs when the OUTLN account is reset to use a hard-coded password.
|
2008-04-16
|
Oracle Database Core RDBMS Session Creation Unspecified Remote Issue
|
|
44509
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) SDO_UTIL in the Oracle Spatial component, aka DB05; or (2) fine grained auditing in the Audit component, aka DB14. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB05 is SQL injection.
|
2008-04-16
|
Oracle Database Spatial SDO_UTIL Unspecified SQL Injection
|
|
44510
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote unauthenticated or authenticated attack vectors related to (1) SYS.DBMS_AQ in the Advanced Queuing component, aka DB01; (2) Core RDBMS, aka DB03; (3) SDO_GEOM in Oracle Spatial, aka DB06; (4) Export, aka DB12; and (5) DBMS_STATS in Query Optimizer, aka DB13. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB06 is SQL injection, and DB13 occurs when the OUTLN account is reset to use a hard-coded password.
|
2008-04-16
|
Oracle Database Spatial SDO_GEOM Unspecified SQL Injection
|
|
44511
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 have unknown impact and remote attack vectors related to (1) SDO_IDX in the Spatial component, aka DB07; and (2) Core RDBMS, aka DB10. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB07 is SQL injection.
|
2008-04-16
|
Oracle Database Spatial SDO_IDX Unspecified SQL Injection
|
|
44512
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.
|
2008-04-16
|
Oracle Database Authentication Unspecified Remote Information Disclosure
|
|
44513
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Net Services component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and local attack vectors, aka DB09.
|
2008-04-16
|
Oracle Database Net Services Unspecified Local Issue
|
|
44507
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 have unknown impact and remote attack vectors related to (1) SDO_IDX in the Spatial component, aka DB07; and (2) Core RDBMS, aka DB10. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB07 is SQL injection.
|
2008-04-16
|
Oracle Database Core RDBMS Session Creation Unspecified Remote Information Disclosure
|
|
44515
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote unauthenticated or authenticated attack vectors related to (1) SYS.DBMS_AQ in the Advanced Queuing component, aka DB01; (2) Core RDBMS, aka DB03; (3) SDO_GEOM in Oracle Spatial, aka DB06; (4) Export, aka DB12; and (5) DBMS_STATS in Query Optimizer, aka DB13. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB06 is SQL injection, and DB13 occurs when the OUTLN account is reset to use a hard-coded password.
|
2008-04-16
|
Oracle Database Direct Path Export 0x5B Message Remote Information Disclosure
|
|
44517
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) SDO_UTIL in the Oracle Spatial component, aka DB05; or (2) fine grained auditing in the Audit component, aka DB14. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB05 is SQL injection.
|
2008-04-16
|
Oracle Database Audit Table Subject Insertion Unspecified Remote Issue
|
|
44504
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+, and 10.1.0.5 has unknown impact and remote attack vectors related to SYS.DBMS_AQJMS_INTERNAL, aka DB15. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that DB15 is for multiple buffer overflows in the (1) AQ$_REGISTER and (2) AQ$_UNREGISTER procedures.
|
2008-04-16
|
Oracle Database Advanced Queuing SYS.DBMS_AQJMS_INTERNAL Unspecified Remote DoS
|
|
43980
Description:
A buffer overflow exists in Safari. The WebKit component fails to validate JavaScript regular expressions resulting in a heap overflow. With a specially crafted web page, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2008-04-16
|
Apple Safari WebKit (JavaScriptCore/pcre/pcre_compile.cpp) PCRE Nested Repetition Count Overflow
|
|
48899
Description:
Unknown / Incomplete
|
2008-04-16
|
Deliantra Server Shops Converters Unspecified Issue
|
|
44450
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.
|
2008-04-16
|
xine-lib NSF src/demuxers/demux_nsf.c demux_nsf_send_chunk Function Remote Overflow
|
|
44410
Description:
AutoTutorials contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'viewcat.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-04-16
|
AutoTutorials viewcat.php id Parameter SQL Injection
|
|
44414
Description:
Security Assurance Team of the National Australia Bank have reported a vulnerability in the Jom Comment component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to unspecified parameters is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
|
2008-04-16
|
Jom Comment Component for Joomla! Unspecified SQL Injection
|
|
44452
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in bs_auth.php in Blogator-script 0.95 and 1.01 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-16
|
Blogator-script bs_auth.php msg Parameter XSS
|
|
44731
Description:
(Description Provided by CVE) : option_Update.asp in Carbon Communities 2.4 and earlier allows remote attackers to edit arbitrary member information via a modified ID field.
|
2008-04-16
|
Carbon Communities option_Update.asp ID Field Arbitrary Member Information Modification
|
|
53328
Description:
(Description Provided by CVE) : Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .SRT file.
|
2008-04-16
|
BS.player SRT File Handling Overflow
|
|
51170
Description:
Unknown / Incomplete
|
2008-04-15
|
WordPress SECRET_KEY Configuration Weakness
|
|
51166
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Gallarific Free Edition allow remote attackers to inject arbitrary web script or HTML via (1) the e-mail address, (2) a comment, which is not properly handled during moderation, and (3) the tag parameter to gallery/tags.php.
|
2008-04-15
|
Gallarific E-mail Address Field XSS
|