| OSVDB ID | Disclosure Date | Title |
|
66929
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtf35333.
|
2010-08-04
|
Cisco Unified Wireless Network (UWN) Solution Unspecified XSS
|
|
66930
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Cisco Wireless Control System (WCS) 7.x before 7.0.164, as used in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtg33854.
|
2010-08-04
|
Cisco Wireless Control System searchClientAction.do Unspecified Parameter XSS
|
|
66931
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Cisco Wireless Control System (WCS) 7.x before 7.0.164, as used in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtg33854.
|
2010-08-04
|
Cisco Wireless Control System switchGeneralAction.do Unspecified Parameter XSS
|
|
67007
Description:
(Description Provided by CVE) : Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc77567.
|
2010-08-04
|
Cisco PIX / ASA SunRPC Inspection Feature Crafted UDP Packet Remote DoS (2010-1578)
|
|
67008
Description:
(Description Provided by CVE) : Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc79922.
|
2010-08-04
|
Cisco PIX / ASA SunRPC Inspection Feature Crafted UDP Packet Remote DoS (2010-1579)
|
|
67009
Description:
(Description Provided by CVE) : Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc85753.
|
2010-08-04
|
Cisco PIX / ASA SunRPC Inspection Feature Crafted UDP Packet Remote DoS (2010-1580)
|
|
67010
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Transport Layer Security (TLS) implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.17), and 8.3 before 8.3(1.6) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via a sequence of crafted TLS packets, aka Bug ID CSCtd32627.
|
2010-08-04
|
Cisco PIX / ASA TLS Implementation Crafted Packet Sequence Remote DoS (2010-1581)
|
|
67012
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Transport Layer Security (TLS) implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.17), and 8.3 before 8.3(1.6) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via a sequence of crafted TLS packets, aka Bug ID CSCtf37506.
|
2010-08-04
|
Cisco PIX / ASA TLS Implementation Crafted Packet Sequence Remote DoS (2010-2814)
|
|
67013
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Transport Layer Security (TLS) implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.17), and 8.3 before 8.3(1.6) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via a sequence of crafted TLS packets, aka Bug ID CSCtf55259.
|
2010-08-04
|
Cisco PIX / ASA TLS Implementation Crafted Packet Sequence Remote DoS (2010-2815)
|
|
67015
Description:
(Description Provided by CVE) : Unspecified vulnerability in the IKE implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.10), and 8.3 before 8.3(1.1) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via a crafted IKE message, aka Bug ID CSCte46507.
|
2010-08-04
|
Cisco PIX / ASA IKE Implementation Crafted Message Remote DoS
|
|
67078
Description:
Unknown / Incomplete
|
2010-08-04
|
EJBCA Admin Interface Unspecified XSS
|
|
68757
Description:
Unknown / Incomplete
|
2010-08-04
|
Quick 'n Easy FTP Server USER Command Overflow Remote DoS
|
|
68784
Description:
Unknown / Incomplete
|
2010-08-04
|
K-Meleon about:neterror URL Handling Overflow DoS
|
|
68783
Description:
Unknown / Incomplete
|
2010-08-04
|
Apple Safari URL Handling Overflow DoS
|
|
66830
Description:
(Description Provided by CVE) : Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue.
|
2010-08-03
|
Citrix Multiple Product ICA Connection Graphics Packet Handling Remote Code Execution
|
|
66829
Description:
(Description Provided by CVE) : The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp & XenDesktop before 12.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document that triggers the reading of a .ICA file.
|
2010-08-03
|
Citrix XenApp ICAClient Library ActiveX Object Unspecified Arbitrary Code Execution
|
|
66863
Description:
NextGEN Smooth Gallery Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the wp-content/plugins/nextgen-smooth-gallery/nggSmoothFrame.php script not properly sanitizing user-supplied input to the 'galleryID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-08-03
|
NextGEN Smooth Gallery Plugin for WordPress wp-content/plugins/nextgen-smooth-gallery/nggSmoothFrame.php galleryID Parameter SQL Injection
|
|
66827
Description:
(Description Provided by CVE) : Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as demonstrated by JailbreakMe.
|
2010-08-03
|
Apple iOS Kernel Unspecified Local Privilege Escalation
|
|
66932
Description:
(Description Provided by CVE) : Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long OvJavaLocale value in a cookie.
|
2010-08-03
|
HP OpenView Network Node Manager (OV NNM) webappmon.exe OvJavaLocale Cookie Value Handling Remote Overflow
|
|
66814
Description:
Amlibweb Library Management System is prone to an overflow condition. webquery.dll fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted request, a remote attacker can potentially cause arbitrary code execution.
|
2010-08-03
|
Amlib Amlibweb Library Management System webquery.dll app Parameter Overflow
|
|
66917
Description:
Unknown / Incomplete
|
2010-08-03
|
avast! Internet Security aswFW.sys IOCTL Handling Local Overflow DoS
|
|
66935
Description:
Unknown / Incomplete
|
2010-08-03
|
Novell ZENworks Multiple Products Common Password Cross-session Remote Authentication Bypass
|
|
66891
Description:
(Description Provided by CVE) : phpCAS before 1.1.2 allows remote authenticated users to hijack sessions via a query string containing a crafted ticket value.
|
2010-08-03
|
phpCAS Crafted Ticket Value Query String Session Hijack
|
|
66890
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the convert_to_idna function in WWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed URL containing a % (percent) character in the domain name.
|
2010-08-03
|
Lynx HTParse.c convert_to_idna() Function URL Handling Remote Overflow
|
|
66892
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in phpCAS before 1.1.2, when proxy mode is enabled, allows remote attackers to inject arbitrary web script or HTML via a callback URL.
|
2010-08-03
|
phpCAS Proxy Mode Callback URL XSS
|
|
67348
Description:
FuseTalk contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'FTVAR_SORT' parameter upon submission to the 'categories.aspx' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-08-03
|
FuseTalk categories.aspx FTVAR_SORT Parameter XSS
|
|
67844
Description:
(Description Provided by CVE) : The Limit Mail feature in the Parental Controls functionality in Mail on Apple Mac OS X does not properly enforce the correspondence whitelist, which allows remote attackers to bypass intended access restrictions and conduct e-mail communication by leveraging knowledge of a child's e-mail address and a parent's e-mail address, related to parental notification of unapproved e-mail addresses.
|
2010-08-03
|
Apple Mac OS X Mail Parental Controls Unspecified Unauthorized Sender Whitelist
|
|
70651
Description:
FFmpeg is prone to an overflow condition. The 'vorbis_residue_decode_internal' function in 'libavcodec/vorbis_dec.c' in the Vorbis decoder fails to properly sanitize user-supplied input resulting in an integer overflow. Through unspecified means, a remote attacker can potentially cause an unspecified impact.
|
2010-08-03
|
FFmpeg Vorbis Decoder libavcodec/vorbis_dec.c vorbis_residue_decode_internal Function Overflow
|
|
86375
Description:
Wind River Systems' VxWorks contains a flaw that may lead to unauthorized access. Due to a weakness in the password hashing algorithm, there are only ~ 210,000 combinations for a valid password. If you remove characters that are not easy to type (e.g., high/low ASCII0, the number of permutations drops to ~ 8,000. Since the FTP service allows 4 concurrent connections, and enforces no lockout mechanism for failed password attempts, it only takes ~ 30 minutes at most to brute force a password for any given account.
|
2010-08-02
|
Wind River Systems' VxWorks FTP Service Weak Hasing Algorithm Brute Force Weakness
|
|
66858
Description:
RaidenTunes 2.1.1 suffers from a Cross-Site Scripting (XSS) vulnerability caused by improper validation of user-supplied input by the music_out.php script thru "p" param. A remote attacker could exploit this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site, allowing the attacker to steal the victim's cookie-based authentication credentials.
|
2010-08-02
|
RaidenTUNES music_out.php p Parameter XSS
|
|
66809
Description:
Unknown / Incomplete
|
2010-08-02
|
FTP Commander Directory Download Traversal Arbitrary File Creation
|
|
69008
Description:
By default, IBM Rational Quality Manager and Rational Test Lab Manager Tomcat installs with a default password. The 'manager' account has a password which is publicly known and documented. This allows attackers to trivially access the program or system.
|
2010-08-02
|
IBM Rational Quality Manager and Rational Test Lab Manager Tomcat manager Default Account
|
|
66909
Description:
Wind River Systems' VxWorks contains a flaw that may lead to an unauthorized password exposure. It is possible for a remote attacker to gain access to hashed passwords when the 'INCLUDE_SECURITY' configuration setting is enabled and usernames and passwords are hardcoded by using the 'LOGIN_USER_NAME' and 'LOGIN_USER_PASSWORD' parameters, resulting in a loss of confidentiality.
|
2010-08-02
|
Wind River Systems' VxWorks INCLUDE_SECURITY Functionality Multiple Parameter Hardcoded Credentials Creation
|
|
66808
Description:
Unknown / Incomplete
|
2010-08-02
|
32bit FTP Directory Download Traversal Arbitrary File Creation
|
|
66843
Description:
VxWorks contains a flaw that may allow an attacker to brute force a known backdoor account over FTP with trivial effort. The issue is triggered in combination with a flaw that allows arbitrary memory access, which allows the backdoor account name to be discovered.
|
2010-08-02
|
Wind River Systems' VxWorks loginLib Default Hashing Algorithm Weakness
|
|
66842
Description:
VxWorks contains a flaw that may allow a remote attacker to read and write arbitrary memory on the device. The issue is triggered by leaving the WDB target agent debug service enabled by default.
|
2010-08-02
|
Wind River Systems' VxWorks WDB Debug Service Remote Arbitrary Memory Manipulation
|
|
66910
Description:
Wind River Systems' VXWorks FTP daemon contains a flaw that may lead to an unauthorized information disclosure. The issue is due to the application not restricting the number of invalid login attempts a client can make. This may allow a remote attacker to more easily conduct brute force attacks and disclose user accounts.
|
2010-08-02
|
Wind River Systems' VxWorks FTP Daemon TCP Connection Termination Weakness
|
|
66971
Description:
FuseTalk contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'keyword' parameter upon submission to the 'usersearchresults.cfm' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-08-02
|
FuseTalk usersearchresults.cfm keyword Parameter XSS
|
|
68631
Description:
(Description Provided by CVE) : arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.
|
2010-08-02
|
Linux Kernel on RHEL VMCS arch/x86/hvm/vmx/vmcs.c Hardware Support Verification Weakness Host OS Local DoS
|
|
70342
Description:
Cisco Adaptive Security Appliances (ASA) contains a flaw that may allow a remote denial of service. The issue is triggered when an unspecified vulnerability is exploited, allowing a remote attacker to cause a denial of service via LAN-to-LAN IPsec session saturation.
|
2010-08-02
|
Cisco Adaptive Security Appliances (ASA) LAN-to-LAN IPsec Session Saturation Remote DoS
|