| OSVDB ID | Disclosure Date | Title |
|
58413
Description:
Oracle Document Capture contains a flaw that may allow a malicious user to compromise a users system. The issue is triggered when a design error in the BLACKICEDEVMODE.BlackIceDEVMODECtrl.1 ActiveX control (BlackIceDEVMODE.ocx) occurs. It is possible that the flaw may allow execution of arbitrary commands when a document is printed using the altered printer, resulting in a loss of integrity.
|
2009-09-30
|
Oracle Document Capture BLACKICEDEVMODE.BlackIceDEVMODECtrl.1 ActiveX (BlackIceDEVMODE.ocx) Multiple Method Arbitrary Command Execution
|
|
58417
Description:
BIGACE Web CMS contains a flaw that allows a remote Cross-Site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps and/or confirmation for sensitive transactions. By using a crafted URL (e.g. a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2009-09-30
|
BIGACE Web CMS Admin Account Creation CSRF
|
|
58420
Description:
(Description Provided by CVE) : Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.
|
2009-09-30
|
IBM Installation Manager IBMIM.exe iim: URL Library Argument Injection Arbitrary Code Execution
|
|
58423
Description:
A remote overflow exists in KeyHelp. KeyHelp fails to check an input boundary in the KeyHelp.KeyCtrl.1 ActiveX control (KeyHelp.ocx) resulting in a stack-based buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2009-09-30
|
KeyWorks KeyHelp KeyHelp.KeyCtrl.1 ActiveX (KeyHelp.ocx) Multiple Method Overflow
|
|
58424
Description:
Boost Module for Drupal contains a flaw related to an unspecified feature that may allow an attacker to create a directory in the webroot. No further details have been provided.
|
2009-09-30
|
Boost Module for Drupal Unspecified Directory Creation
|
|
58444
Description:
Browscap Module for Drupal contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate values in the HTTP User-Agent header upon submission. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-09-30
|
Browscap Module for Drupal HTTP User-Agent Header XSS
|
|
58445
Description:
Organic Groups module for Drupal contains a flaw that allows a remote cross site scripting attack. This flaw exists because the the Organic Groups module does not properly sanitize input passed while creating new groups before being displayed. This could allow a malicious user to execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-09-30
|
Organic Groups Module for Drupal New Group Creation XSS
|
|
58449
Description:
Sun Solaris contains a flaw that may allow a local denial of service. The issue is triggered when a memory leak in the Solaris IP module occurs, and will result in loss of availability for the system.
|
2009-09-30
|
Solaris Kernel IP Module Unspecified Local DoS
|
|
58516
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in modules/tickets/functions_ticketsui.php in Kayako SupportSuite and eSupport 3.60.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the staff control panel, a different vector than CVE-2007-1145.
|
2009-09-30
|
Kayako SupportSuite / eSupport modules/tickets/functions_ticketsui.php Staff Control Panel XSS
|
|
58450
Description:
Sun Solaris contains a flaw that may allow a local denial of service. The issue is triggered when a memory leak in the STREAM Framework occurs, and will result in loss of availability for the system.
|
2009-09-30
|
Solaris STREAMS Framework Unspecified Local DoS
|
|
58474
Description:
PI Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the default authentication mechanism is exploited, which will disclose confidential operational information resulting in a loss of confidentiality.
|
2009-09-30
|
PI Server Authentication Process Encryption Weakness
|
|
58495
Description:
(Description Provided by CVE) : A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory, related to requirements for directory ownership.
|
2009-09-30
|
OpenSSH sshd ChrootDirectory Feature SetUID Hard Link Local Privilege Escalation
|
|
58612
Description:
Unknown / Incomplete
|
2009-09-30
|
Linksys WRT54GC Multiple Parameter CSRF
|
|
58614
Description:
(Description Provided by CVE) : The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
|
2009-09-30
|
McAfee Email and Web Security Appliance TCP/IP Implementation Queue Connection Saturation TCP State Table Remote DoS
|
|
58892
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Dex 5.x-1.0 and earlier and 6.x-1.0-rc1 and earlier, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2009-09-30
|
Dex Module for Drupal Unspecified XSS
|
|
58894
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the additional links interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote authenticated users, with "administer site configuration" permission, to inject arbitrary web script or HTML via unspecified vectors, related to link path output.
|
2009-09-30
|
Sitemap Module for Drupal Link Path Output XSS
|
|
58896
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.
|
2009-09-30
|
Shared Sign-On Module for Drupal Unspecified CSRF
|
|
58898
Description:
(Description Provided by CVE) : Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors.
|
2009-09-30
|
Shared Sign-On Module for Drupal Unspecified Session Fixation
|
|
59081
Description:
(Description Provided by CVE) : Integer signedness error in the ax25_setsockopt function in net/ax25/af_ax25.c in the ax25 subsystem in the Linux kernel before 2.6.31.2 allows local users to cause a denial of service (OOPS) via a crafted optlen value in an SO_BINDTODEVICE operation.
|
2009-09-30
|
Linux Kernel ax25 Subsystem net/ax25/af_ax25.c ax25_setsockopt Function Local DoS
|
|
60434
Description:
(Description Provided by CVE) : The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.
|
2009-09-29
|
PHP ext/standard/file.c tempnam() Function safe_mode Bypass
|
|
60435
Description:
(Description Provided by CVE) : The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.
|
2009-09-29
|
PHP ext/posix/posix.c posix_mkfifo() Function open_basedir Bypass
|
|
58447
Description:
A remote overflow exists in Novell Netware. An error in the portmapper daemon 'PKERNEL.NLM' when handling RPC calls resulting in a buffer overflow. With a specially crafted request, an attacker can cause execution of arbitrary code resulting in a loss of integrity.
|
2009-09-29
|
Novell NetWare PKERNEL.NLM CALLIT RPC Call Handling Overflow
|
|
58394
Description:
HP Remote Graphics Software contains a flaw related to access restrictions that may allow an attacker to gain unauthorized privileges. No further details have been provided.
|
2009-09-29
|
HP Remote Graphics Software (RGS) Unspecified Access Restriction Bypass
|
|
58409
Description:
(Description Provided by CVE) : gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
|
2009-09-29
|
IBM AIX gssd NFSv4 Kerberos Credential Cache Network Share Local Access Restriction Bypass
|
|
58410
Description:
(Description Provided by CVE) : nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.
|
2009-09-29
|
IBM AIX nfs.ext NFSv4 nfs_portmon Tunable Network Share Remote Access Restriction Bypass
|
|
58418
Description:
Adobe Photoshop Elements contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered due to the insecure Discretionary Access Control List (DACL) for the "Adobe Active File Monitor V8" service. This flaw may lead to a loss of integrity.
|
2009-09-29
|
Adobe Photoshop Elements Active File Monitor V8 Service Discretionary Access Control List Local Privilege Escalation
|
|
58459
Description:
SERV-U contains a flaw that may allow a remote denial of service. The issue is triggered when an error within the handling of the 'SITE SET TRANSFERPROGRESS ON' occurs, and will result in loss of availability for the server.
|
2009-09-29
|
Serv-U SITE SET TRANSFERPROGRESS ON Command Handling DoS
|
|
59281
Description:
Unknown / Incomplete
|
2009-09-29
|
python-markdown2 Image Reference Attributes XSS
|
|
60549
Description:
InterSystems Cache is prone to an overflow condition. The HTTP server fails to properly sanitize user-supplied input resulting in a stack overflow. With a specially crafted GET request, a remote attacker can potentially execute arbitrary code.
|
2009-09-29
|
InterSystems Cache / Ensemble CSP Gateway UtilConfigHome.csp GET Request Handling Remote Overflow
|
|
60630
Description:
Interspire Knowledge Manager contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the 'dialog/file_manager.php' not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'p' parameter. This directory traversal attack would allow the attacker to access arbitrary files.
|
2009-09-29
|
Interspire Knowledge Manager dialog/file_manager.php p Parameter Traversal Arbitrary File Access
|
|
68219
Description:
phplist contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /lists/admin/index.php script not properly sanitizing user-supplied input to the 'forgotpassword' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-09-29
|
phplist /lists/admin/index.php forgotpassword Parameter SQL Injection
|
|
58379
Description:
Unknown / Incomplete
|
2009-09-28
|
SAP GUI EAI WebViewer2D ActiveX (WebViewer2D.dll) SaveToSessionFile() Method Arbitrary File Overwrite
|
|
58381
Description:
iCRM Basic Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'p3' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-09-28
|
iCRM Basic Component for Joomla! index.php p3 Parameter SQL Injection
|
|
58380
Description:
Unknown / Incomplete
|
2009-09-28
|
SAP GUI EAI WebViewer3D ActiveX (WebViewer3D.dll) Multiple Method Arbitrary File Overwrite
|
|
58382
Description:
(Description Provided by CVE) : A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2009-09-28
|
iCRM Basic Component for Joomla! Admin Interface Authentication Bypass
|
|
58446
Description:
(Description Provided by CVE) : The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.6.1.309, 4.7.0 before 4.7.0.179, and 4.7.1 before 4.7.1.57 does not properly handle "hidden" characters including a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
|
2009-09-28
|
BlackBerry Device Software Browser X.509 Certificate Authority (CA) Common Name Null Byte Handling SSL MiTM Weakness
|
|
58387
Description:
A remote overflow exists in CuteFTP. CuteFTP fails to check proper bounds on site labels resulting in a buffer overflow. With a specially crafted site label entry, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2009-09-28
|
CuteFTP Site Label Handling Overflow
|
|
58425
Description:
FireFTP Extension for Firefox contains a flaw that may allow a malicious user to inject command arguments. The issue is triggered when src/content/js/connection/sftp.js and src/content/js/connection/controlSocket.js.in fail to properly encode filenames with double quotes. It is possible that the flaw may allow argument injection resulting in a loss of integrity.
|
2009-09-28
|
FireFTP Extension for Firefox SFTP Filename Handling Argument Injection
|
|
58494
Description:
(Description Provided by CVE) : TrustPort Antivirus before 2.8.0.2266 and PC Security before 2.0.0.1291 use weak permissions (Everyone: Full Control) for files under %PROGRAMFILES%, which allows local users to gain privileges by replacing executables with Trojan horse programs.
|
2009-09-28
|
TrustPort Multiple Products Directory Permission Weakness Local Privilege Escalation
|
|
58477
Description:
DB2 contains a flaw related to the table drop function definer that may allow an attacker to unspecified impact. No further details have been provided.
|
2009-09-28
|
IBM DB2 Universal Database Table Drop Function Definer Unspecified Issue
|