| OSVDB ID | Disclosure Date | Title |
|
62434
Description:
(Description Provided by CVE) : Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.2), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.16); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCsy91157.
|
2010-02-17
|
Cisco Multiple Products SIP Message Processing Unspecified Remote DoS (2010-0150)
|
|
62435
Description:
(Description Provided by CVE) : Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.2), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.16); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCtc96018.
|
2010-02-17
|
Cisco Multiple Products SIP Message Processing Unspecified Remote DoS (2010-0569)
|
|
62432
Description:
(Description Provided by CVE) : The Cisco Firewall Services Module (FWSM) 4.0 before 4.0(8), as used in for the Cisco Catalyst 6500 switches, Cisco 7600 routers, and ASA 5500 Adaptive Security Appliances, allows remote attackers to cause a denial of service (crash) via a malformed Skinny Client Control Protocol (SCCP) message.
|
2010-02-17
|
Cisco Multiple Products SCCP Inspection Malformed Skinny Control Message Handling Remote DoS
|
|
62430
Description:
(Description Provided by CVE) : Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.2 before 7.2(4.45), 8.0 before 8.0(4.44), 8.1 before 8.1(2.35), and 8.2 before 8.2(1.10), allows remote attackers to cause a denial of service (page fault and device reload) via a malformed DTLS message, aka Bug ID CSCtb64913 and "WebVPN DTLS Denial of Service Vulnerability."
|
2010-02-17
|
Cisco ASA 5500 Series WebVPN Malformed DTLS Message Remote DoS
|
|
62431
Description:
(Description Provided by CVE) : Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(4.44), 8.1 before 8.1(2.35), and 8.2 before 8.2(1.10) allows remote attackers to cause a denial of service (device reload) via a malformed TCP segment when certain NAT translation and Cisco AIP-SSM configurations are used, aka Bug ID CSCtb37219.
|
2010-02-17
|
Cisco ASA 5500 Series Malformed TCP Segment Handling Remote DoS
|
|
62436
Description:
(Description Provided by CVE) : Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.1), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.15); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (active IPsec tunnel loss and prevention of new tunnels) via a malformed IKE message through an existing tunnel to UDP port 4500, aka Bug ID CSCtc47782.
|
2010-02-17
|
Cisco Multiple Products Malformed IKE Message Handling Remote DoS
|
|
62437
Description:
(Description Provided by CVE) : Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.7), 8.1 before 8.1(2.40), and 8.2 before 8.2(2.1); and Cisco PIX 500 Series Security Appliance; allows remote attackers to bypass NTLMv1 authentication via a crafted username, aka Bug ID CSCte21953.
|
2010-02-17
|
Cisco Multiple Products Crafted Username NTLMv1 Authentication Bypass
|
|
62444
Description:
Cisco Security Agents Management Center contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to an unspecified script not properly sanitizing user-supplied input to an unspecified parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-17
|
Cisco Security Agents Management Center Unspecified SQL Injection
|
|
62445
Description:
(Description Provided by CVE) : Unspecified vulnerability in Cisco Security Agent 5.2 before 5.2.0.285, when running on Linux, allows remote attackers to cause a denial of service (kernel panic) via "a series of TCP packets."
|
2010-02-17
|
Cisco Security Agents Crafted TCP Packet Handling Remote DoS
|
|
62452
Description:
Kusaba X contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'reportreason' parameter when reporting a post. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-17
|
Kusaba Post Reports reportreason Parameter XSS
|
|
62651
Description:
Auktionshaus Gelb contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'news.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-17
|
Auktionshaus Gelb news.php id Parameter SQL Injection
|
|
62716
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Emweb Wt before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to "insertions of the URL" that occur during a redirection.
|
2010-02-17
|
Wt Redirection URL Insertion XSS
|
|
62717
Description:
(Description Provided by CVE) : Emweb Wt before 3.1.1 does not validate the UTF-8 encoding of (1) form values and (2) JSignal arguments, which has unspecified impact and remote attack vectors.
|
2010-02-17
|
Wt UTF-8 Data Handling Unspecified Issue
|
|
62768
Description:
Help Inject module for Drupal contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'page' field upon submission to the 'Create Book page' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-17
|
Help Inject Module for Drupal Book page Field XSS
|
|
63201
Description:
SphereCMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'archive.php' script not properly sanitizing user-supplied input to the 'view' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-17
|
SphereCMS archive.php view Parameter SQL Injection
|
|
64817
Description:
Pixel Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the products_list_fa.asp script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-17
|
Pixel Portal products_list_fa.asp id Parameter SQL Injection
|
|
67687
Description:
(Description Provided by CVE) : The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users to cause a denial of service or have unspecified other impact by writing to this file.
|
2010-02-17
|
IBM DB2 Universal Database Self Tuning Memory Manager (STMM) STMM Log File Permission Weakness
|
|
62361
Description:
httpdx contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the included FTP server not properly sanitizing user supplied input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow the attacker to upload or download arbitrary files from parent directories, up to the globally configured "chroot" directory.
|
2010-02-16
|
httpdx FTP Server Traversal Arbitrary File Access
|
|
62371
Description:
(Description Provided by CVE) : gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, which allows physically proximate attackers to bypass screen locking and access an unattended workstation by connecting and disconnecting monitors multiple times, a related issue to CVE-2010-0414.
|
2010-02-16
|
gnome-screensaver Monitor Topology Change Security Bypass Weakness
|
|
62391
Description:
(Description Provided by CVE) : The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request.
|
2010-02-16
|
MIT Kerberos 5 Key Distribution Center (KDC) Authorization Data Request Remote DoS
|
|
62344
Description:
KDPics contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'categories' parameter upon submission to the 'galeries.inc.php3' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-16
|
KDPics galeries.inc.php3 categories Parameter XSS
|
|
62345
Description:
KDPics contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions such as add new users. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-02-16
|
KDPics New User Addition CSRF
|
|
62356
Description:
ASPCode CMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'email' parameter (when 'sec' is set to '33' and 'ma1' is set to 'forgotpass'), 'name', 'email', 'website', and 'message' parameters (when 'sec' is set to '23', 'ma1' is set to 'message', and 'a2' is set to 'form'), and arbitrary parameters when 'sec' is set, upon submission to the 'default.asp' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-16
|
ASPCode CMS default.asp Multiple Parameter XSS
|
|
62353
Description:
Free Google Page Ranks contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'url' parameter upon submission to the 'pagerank.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-16
|
Free Google Page Ranks pagerank.php url Parameter XSS
|
|
62354
Description:
Netzbrett contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered due to improper access restrictions on the dump.php script, which will disclose the database backup to a remote attacker.
|
2010-02-16
|
Netzbrett dump.php Direct Request Database Disclosure
|
|
62357
Description:
ASPCode CMS contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions such as add or delete users. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-02-16
|
ASPCode CMS default.asp User Account Creation / Deletion CSRF
|
|
62358
Description:
ASPCode CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'default.asp' script not properly sanitizing user-supplied input to the 'newsid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-16
|
ASPCode CMS default.asp newsid Parameter SQL Injection
|
|
62362
Description:
superengine CMS Custom Pack contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-16
|
superengine CMS Custom Pack index.php id Parameter SQL Injection
|
|
62363
Description:
BGS CMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'search' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-16
|
BGS CMS index.php search Parameter XSS
|
|
62390
Description:
RWCards Component for Joomla! contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the 'index.php'script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) and URL-encoded NULL bytes, supplied via the 'controller' parameter(when "option" is set to "com_rwcards"). This directory traversal attack would allow the attacker to include arbitrary files from local resources.
|
2010-02-16
|
RWCards Component for Joomla! index.php controller Parameter Traversal Arbitrary File Access
|
|
62451
Description:
(Description Provided by CVE) : The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asterisk Business Edition B.x.x and C.x.x, when using the ${EXTEN} channel variable and wildcard pattern matches, allows context-dependent attackers to inject strings into the dialplan using metacharacters that are injected when the variable is expanded, as demonstrated using the Dial application to process a crafted SIP INVITE message that adds an unintended outgoing channel leg. NOTE: it could be argued that this is not a vulnerability in Asterisk, but a class of vulnerabilities that can occur in any program that uses this feature without the associated filtering functionality that is already available.
|
2010-02-16
|
Asterisk Dialplan Wildcard Pattern Configuration Manipulation
|
|
62551
Description:
(Description Provided by CVE) : The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.
|
2010-02-16
|
cronie crontab.c edit_cmd Function Temporary File Symlink Local Privilege Escalation
|
|
62771
Description:
Unknown / Incomplete
|
2010-02-16
|
Realname CCK User Reference Module for Drupal Autocomplete Information Disclosure
|
|
64819
Description:
Unknown / Incomplete
|
2010-02-16
|
Trusteer RapportMgmtService.exe Manipulation Service Bypass
|
|
77229
Description:
Unknown / Incomplete
|
2010-02-15
|
Cisco Architecture for Lawful Intercept in IP Networks SNMP Trap Failure Audit Trail Weakness
|
|
77230
Description:
Unknown / Incomplete
|
2010-02-15
|
Cisco Architecture for Lawful Intercept in IP Networks SNMP TAP-MIB Remote Audit Trail Disable Weakness
|
|
62346
Description:
Copperleaf Photolog for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'cpl/cplphoto.php' script not properly sanitizing user-supplied input to the 'postid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-15
|
Copperleaf Photolog Plugin for WordPress cpl/cplphoto.php postid Parameter SQL Injection
|
|
62338
Description:
Unknown / Incomplete
|
2010-02-15
|
NetAdvantage WebHtmlEditor Component InitialDirectory Parameter Traversal Directory Access
|
|
62339
Description:
Katalog Stron Hurricane contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'get' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-15
|
Katalog Stron Hurricane index.php get Parameter SQL Injection
|
|
62340
Description:
Katalog Stron Hurricane contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'includes/moderation.php' script not properly sanitizing user input supplied to the 'includes_directory' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-02-15
|
Katalog Stron Hurricane includes/moderation.php includes_directory Parameter Remote File Inclusion
|