| OSVDB ID | Disclosure Date | Title |
|
59488
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the sanitizing algorithm.
|
2009-10-22
|
Typo3 Core t3lib_div::quoteJSvalue API Function XSS
|
|
59489
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Frontend Login Box (aka felogin) subcomponent in TYPO3 4.2.0 through 4.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
|
2009-10-22
|
Typo3 Core Frontend Login Box (felogin) Unspecified XSS
|
|
59490
Description:
(Description Provided by CVE) : The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.
|
2009-10-22
|
Typo3 Core Install Tool MD5 Hash Authentication Bypass
|
|
59491
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
|
2009-10-22
|
Typo3 Core Install Tool Unspecified URL Parameter XSS
|
|
59922
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are returned by the getConfigurations function, aka Bug Id 6822057.
|
2009-10-22
|
Sun Java SE X11 / Win32GraphicsDevice Subsystems getConfigurations Function Clone Array Failure Multiple Unspecified Issues
|
|
59921
Description:
(Description Provided by CVE) : The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512.
|
2009-10-22
|
Sun Java SE JRE Abstract Window Toolkit (AWT) Logger Object Restriction Information Disclosure
|
|
59920
Description:
(Description Provided by CVE) : The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.
|
2009-10-22
|
Sun Java SE TimeZone.getTimeZone Method tz File Handling Local File Enumeration
|
|
61433
Description:
Unknown / Incomplete
|
2009-10-22
|
avast! 400.vps Permission Weakness File Deletion Local DoS
|
|
62359
Description:
Auktionshaus contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'news.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-10-22
|
Auktionshaus news.php id Parameter SQL Injection
|
|
59121
Description:
By default, JD Edwards EnterpriseOne Tools installs with a default password. An unspecified database account has a hardcoded and unchangeable password. This could allow attackers to trivially access the database.
|
2009-10-21
|
Oracle JD Edwards Tools Default Hardcoded Database Password
|
|
59114
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Communications Order and Service Management component in Oracle Industry Applications 2.8.0, 6.2.0, 6.3.0, and 6.3.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
|
2009-10-21
|
Oracle Communications Order and Service Management HTTP Unspecified Issue
|
|
59184
Description:
(Description Provided by CVE) : Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
|
2009-10-21
|
Poppler XRef.cc ObjectStream::ObjectStream Function PDF Handling Overflow
|
|
59183
Description:
(Description Provided by CVE) : Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
|
2009-10-21
|
Xpdf XRef.cc ObjectStream::ObjectStream Function PDF Handling Overflow
|
|
59107
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
|
2009-10-21
|
Oracle Database Core RDBMS Unspecified Remote Compromise
|
|
59110
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.
|
2009-10-21
|
Oracle Database Network Authentication AUTH_SESSKEY Parameter Remote Overflow
|
|
59111
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
|
2009-10-21
|
Oracle Database Network Authentication Unspecified Remote Compromise (2009-1985)
|
|
59099
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DMP_SYS.
|
2009-10-21
|
Oracle Database Data Mining SYS.DMP_SYS Unspecified Remote Issue
|
|
59106
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability, related to MDSYS.PRVT_CMT_CBK.
|
2009-10-21
|
Oracle Database Spatial MDSYS.PRVT_CMT_CBK Unspecified Remote Issue
|
|
59105
Description:
(Description Provided by CVE) : Unspecified vulnerability in the PL/SQL component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
|
2009-10-21
|
Oracle Database PL/SQL Procedure Creation Unspecified Remote Issue
|
|
59108
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Application Express component in Oracle Database 3.0.1 allows remote authenticated users to affect confidentiality and integrity, related to FLOWS_030000.WWV_EXECUTE_IMMEDIATE.
|
2009-10-21
|
Oracle Database Application Express FLOWS_030000. WWV_EXECUTE_IMMEDIATE Unspecified Remote Issue
|
|
59112
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LTRIC (WMSYS.LTRIC).
|
2009-10-21
|
Oracle Database Workspace Manager SYS.LTRIC (WMSYS.LTRIC) Unspecified Remote Issue
|
|
59115
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
|
2009-10-21
|
Oracle Database Workspace Manager Unspecified Remote Issue
|
|
59101
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
|
2009-10-21
|
Oracle Database on Windows Net Foundation Layer Unspecified Remote Issue
|
|
59103
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Authentication component in Oracle Database 10.2.0.3 and 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors.
|
2009-10-21
|
Oracle Database Authentication Unspecified Remote Information Disclosure (2009-1997)
|
|
59104
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors.
|
2009-10-21
|
Oracle Database Authentication Unspecified Remote Information Disclosure (2009-2000)
|
|
59109
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_AQ_INV.
|
2009-10-21
|
Oracle Database Advanced Queuing SYS.DBMS_AQ_INV Unspecified Remote Issue
|
|
59113
Description:
Oracle Database Text contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the ctxsys.drvxtabc.create_tables script not properly sanitizing user-supplied input to the 'idx_owner' and 'idx_name' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-10-21
|
Oracle Database Text ctxsys.drvxtabc.create_tables Multiple Parameter SQL Injection
|
|
59098
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.7 allows remote authenticated users to affect integrity via unknown vectors.
|
2009-10-21
|
Oracle Database Data Pump Unspecified Remote Issue
|
|
59102
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL and DBMS_SQL.
|
2009-10-21
|
Oracle Database Auditing DBMS_SYS_SQL / DBMS_SQL Unspecified Remote Issue
|
|
59118
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Business Intelligence Enterprise Edition component in unspecified Oracle Application Server versions allows remote attackers to affect integrity via unknown vectors.
|
2009-10-21
|
Oracle Application Server Business Intelligence Enterprise Edition HTTP Unspecified Remote Issue
|
|
59116
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors.
|
2009-10-21
|
Oracle Application Server Portal Unspecified Remote Issue
|
|
59117
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Business Intelligence Enterprise Edition component in Oracle Application Server 10.1.3.4.1 allows local users to affect confidentiality via unknown vectors.
|
2009-10-21
|
Oracle Application Server Business Intelligence Enterprise Edition Unspecified Local Information Disclosure
|
|
59126
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Advanced Benefits component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
|
2009-10-21
|
Oracle E-Business Suite Advanced Benefits HTTP Unspecified Remote Issue
|
|
59130
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Agile Engineering Data Management (EDM) component in Oracle E-Business Suite 6.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
|
2009-10-21
|
Oracle E-Business Suite Agile Engineering Data Management (EDM) ECI Unspecified Remote Issue
|
|
59132
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
|
2009-10-21
|
Oracle E-Business Suite Application Object Library HTTP Unspecified Remote Issue
|
|
59133
Description:
(Description Provided by CVE) : Unspecified vulnerability in the AutoVue component in Oracle E-Business Suite 19.3.2 allows remote attackers to affect availability via unknown vectors.
|
2009-10-21
|
Oracle E-Business Suite AutoVue Unspecified Remote DoS
|
|
59125
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors.
|
2009-10-21
|
Oracle E-Business Suite Application Object Library HTTP Unspecified Remote Issue
|
|
59127
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors.
|
2009-10-21
|
Oracle E-Business Suite Application Object Library Unauthenticated Unspecified Remote Information Disclosure
|
|
59128
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality via unknown vectors.
|
2009-10-21
|
Oracle E-Business Suite Applications Framework Unspecified Remote Information Disclosure
|
|
59131
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows local users to affect confidentiality via unknown vectors.
|
2009-10-21
|
Oracle E-Business Suite Applications Technology Stack Unspecified Local Information Disclosure
|