| OSVDB ID | Disclosure Date | Title |
|
61973
Description:
(Description Provided by CVE) : Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows remote attackers to execute arbitrary code via an SMIL file with crafted string lengths.
|
2010-01-19
|
RealNetworks Multiple Products smlrender.dll SMIL File Handling Overflow
|
|
61983
Description:
(Description Provided by CVE) : SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
|
2010-01-19
|
SUSE Linux postfix Network Interface Remote Access Restriction Bypass
|
|
62007
Description:
(Description Provided by CVE) : Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
|
2010-01-19
|
ISC BIND Recursive Client Query CNAME / DNAME Response DNS Cache Poisoning
|
|
62464
Description:
(Description Provided by CVE) : Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
|
2010-01-19
|
Mozilla Firefox CSS Stylesheet Cross-origin Information Disclosure
|
|
62465
Description:
(Description Provided by CVE) : Opera before 10.10 permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
|
2010-01-19
|
Opera CSS Stylesheet Cross-origin Information Disclosure
|
|
62466
Description:
(Description Provided by CVE) : Microsoft Internet Explorer permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document.
|
2010-01-19
|
Microsoft IE CSS Stylesheet Cross-origin Information Disclosure
|
|
63197
Description:
AdvertisementManager contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'cgi/index.php' script not properly sanitizing user input supplied to the 'req' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-01-19
|
AdvertisementManager cgi/index.php req Parameter Remote File Inclusion
|
|
63468
Description:
(Description Provided by CVE) : The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a .ANI file.
|
2010-01-19
|
Microsoft Windows ANI Parser BITMAPINFO Header Crafted biClrUsed Value DoS
|
|
64374
Description:
Unknown / Incomplete
|
2010-01-19
|
Baidu Security Center FireFoxProxy ActiveX Unspecified Arbitrary Code Execution
|
|
64401
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin/adminlogin.php' script not properly sanitizing user-supplied input to the 'login' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS admin/adminlogin.php login Parameter SQL Injection
|
|
64368
Description:
S.O.M.P.L. Player is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a stack overflow. With a specially crafted M3U file, a remote attacker can potentially cause arbitrary code execution.
|
2010-01-19
|
S.O.M.P.L. Player M3U Playlist File Handling Overflow
|
|
64402
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'bannerclick.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS bannerclick.php id Parameter SQL Injection
|
|
64403
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'comments.php' script not properly sanitizing user-supplied input to the 'article' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS comments.php article Parameter SQL Injection
|
|
64404
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'control.php' script not properly sanitizing user-supplied input to the 'topgroupname' and 'groupname' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS control.php Multiple Parameter SQL Injection
|
|
64405
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'headeruserdata.php' script not properly sanitizing user-supplied input to the 'topgroupname' and 'groupname' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS headeruserdata.php Multiple Parameter SQL Injection
|
|
64406
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'login.php' script not properly sanitizing user-supplied input to the 'subgroupname','groupname','topgroupname' and 'login' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS login.php Multiple Parameter SQL Injection
|
|
64407
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'menu.php' script not properly sanitizing user-supplied input to the 'groupname' and 'topgroupname' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS menu.php Multiple Parameter SQL Injection
|
|
64408
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'module.php' script not properly sanitizing user-supplied input to the 'topgroupname' and 'groupname' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS module.php Multiple Parameter SQL Injection
|
|
64409
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/diary/m_diaryform.php' script not properly sanitizing user-supplied input to the 'DiaryID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/diary/m_diaryform.php DiaryID Parameter SQL Injection
|
|
64410
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/diary/showdiary.php' script not properly sanitizing user-supplied input to the 'month' and 'year' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/diary/showdiary.php Multiple Parameter SQL Injection
|
|
64411
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/diary/showdiarydetail.php' script not properly sanitizing user-supplied input to the 'diaryid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/diary/showdiarydetail.php diaryid Parameter SQL Injection
|
|
64412
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/gallery/m_galleryform.php' script not properly sanitizing user-supplied input to the 'galleryID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/gallery/m_galleryform.php galleryID Parameter SQ Injection
|
|
64413
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/gallery/showgallerydetails.php' script not properly sanitizing user-supplied input to the 'galleryid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/gallery/showgallerydetails.php galleryid Parameter SQL Injection
|
|
64414
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/links/m_linksform.php' script not properly sanitizing user-supplied input to the 'GuestbookID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/links/m_linksform.php GuestbookID Parameter SQL Injection
|
|
64415
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/guestbook/m_guestbookform.php' script not properly sanitizing user-supplied input to the 'LinkID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/guestbook/m_guestbookform.php LinkID Parameter SQL Injection
|
|
64416
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/modfunctions.php' script not properly sanitizing user-supplied input to the 'topgroupname' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/modfunctions.php topgroupname Parameter SQL Injection
|
|
64417
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/news/m_news.php' script not properly sanitizing user-supplied input to the 'NewsID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/news/m_news.php NewsID Parameter SQL Injection
|
|
64418
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/news/shownewsdetails.php' script not properly sanitizing user-supplied input to the 'newsid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/news/shownewsdetails.php newsid Parameter SQL Injection
|
|
64419
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/poll/m_pollform.php' script not properly sanitizing user-supplied input to the 'PollID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/poll/m_pollform.php PollID Parameter SQL Injection
|
|
64420
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/poll/m_polloptiondel.php' script not properly sanitizing user-supplied input to the 'PollOptionID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/poll/m_polloptiondel.php PollOptionID Parameter SQL Injection
|
|
64421
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/poll/m_polloptions.php' script not properly sanitizing user-supplied input to the 'PollID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/poll/m_polloptions.php PollID Parameter SQL Injection
|
|
64422
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/poll/m_polloptionsform.php' script not properly sanitizing user-supplied input to the 'PollOptionID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/poll/m_polloptionsform.php PollOptionID Parameter SQL Injection
|
|
64423
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/reviews/m_reviewsform.php' script not properly sanitizing user-supplied input to the 'reviewsID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/reviews/m_reviewsform.php reviewsID Parameter SQL Injection
|
|
64424
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/reviews/showreviewdetails.php' script not properly sanitizing user-supplied input to the 'reviewsid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS modules/reviews/showreviewdetails.php reviewsid Parameter SQL Injection
|
|
64425
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'printer.php' script not properly sanitizing user-supplied input to the 'article' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS printer.php article Parameter SQL Injection
|
|
64426
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'rateit.php' script not properly sanitizing user-supplied input to the 'article' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS rateit.php article Parameter SQL Injection
|
|
64427
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'selectsite.php' script not properly sanitizing user-supplied input to the 'Site' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS selectsite.php Site Parameter SQL Injection
|
|
64428
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'selecttheme.php' script not properly sanitizing user-supplied input to the 'Theme' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS selecttheme.php Theme Parameter SQL Injection
|
|
64429
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'showcontents.php' script not properly sanitizing user-supplied input to the 'groupname','subgroupname' and 'topgroupname' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS showcontents.php Multiple Parameter SQL Injection
|
|
64430
Description:
ezContents CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'showdetails.php' script not properly sanitizing user-supplied input to the 'contentname' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-01-19
|
ezContents CMS showdetails.php contentname Parameter SQL Injection
|