| OSVDB ID | Disclosure Date | Title |
|
76759
Description:
Unknown / Incomplete
|
2011-10-26
|
eFront Cookie Information Disclosure XSS
|
|
76761
Description:
Unknown / Incomplete
|
2011-10-26
|
eFront install.php upgrade Parameter Database Information Disclosure
|
|
76815
Description:
(Description Provided by CVE) : The Sybase SQL Anywhere database component in Cisco CiscoWorks Common Services 3.x and 4.x before 4.1 allows remote attackers to obtain potentially sensitive information about the engine name and database port via an unspecified request to UDP port 2638, aka Bug ID CSCsk35018.
|
2011-10-26
|
Cisco CiscoWorks Common Services Sybase SQL Anywhere Database Component Request Parsing Remote Information Disclosue
|
|
76643
Description:
Alsbtain Bulletin contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the index.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'act' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-10-25
|
Alsbtain Bulletin index.php act Parameter Traversal Local File Inclusion
|
|
90390
Description:
WebKit contains a flaw in the 'V8DOMWindow::namedPropertyGetter' function in WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp as the return value from GetRealNamedProperty is not ignored. With a specially crafted web page, a context-dependent attacker can bypass the same-origin policy restrictions.
|
2011-10-25
|
WebKit V8DOMWindow::namedPropertyGetter Same Origin Policy Bypass
|
|
76585
Description:
McAfee Web Gateway contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input upon submission to the web interface. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-10-25
|
McAfee Web Gateway Web Interface Unspecified XSS
|
|
76552
Description:
WebKit contains a flaw in the 'HTMLPlugInImageElement::allowedToLoadFrameURL' function [WebCore/html/HTMLPlugInImageElement.cpp] as it accepts JavaScript URIs. With a specially crafted web page, a context-dependent attacker can bypass the same-origin policy restrictions.
|
2011-10-25
|
WebKit HTMLPlugInImageElement::allowedToLoadFrameURL JavaScript URI Same Origin Policy Bypass
|
|
76556
Description:
WebKit contains a use-after-free error in the handling of custom fonts. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2011-10-25
|
WebKit Custom Font Registration Handling Use-after-free Remote Code Execution
|
|
90389
Description:
WebKit contains a flaw in the 'XSLTProcessor::createDocumentFromSource' function in WebCore/xml/XSLTProcessor.cpp as an XSLT-generated document does not inherit its SecurityOrigin from the source document. With a specially crafted web page, a context-dependent attacker can bypass the same-origin policy restrictions.
|
2011-10-25
|
WebKit XSLT-generated Document Security Origin Inheritance Same Origin Policy Bypass
|
|
90388
Description:
WebKit contains a flaw in the 'ScriptController::executeIfJavaScriptURL' function of WebCore/bindings/ScriptControllerBase.cpp as it may be confused by synchronous frame loads. With a specially crafted web page, a context-dependent attacker can bypass the same-origin policy restrictions.
|
2011-10-25
|
WebKit ScriptController::executeIfJavaScriptURL Synchronous Frame Load Confusion Same Origin Policy Bypass
|
|
90450
Description:
WebKit contains a use-after-free error in the 'RenderBlock::updateFirstLetter' function in WebCore/rendering/RenderBlock.cpp as :first-letter after list markers is not updated correctly. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2011-10-25
|
WebKit RenderBlock::updateFirstLetter Style Sheet Handling Use-after-free Remote Code Execution
|
|
90449
Description:
WebKit contains an unspecified use-after-free error in the style sheet handling. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2011-10-25
|
WebKit Unspecified Style Sheet Handling Use-after-free Remote Code Execution
|
|
90448
Description:
WebKit contain a use-after-free error in the 'RenderObjectChildList::updateBeforeAfterContent' function in WebCore/rendering/RenderObjectChildList.cpp that is triggered as styles are not updated on text fragments in :first-letter nested in :before tables. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2011-10-25
|
WebKit RenderObjectChildList::updateBeforeAfterContent Style Sheet Handling Use-after-free
|
|
90447
Description:
WebKit contains a use-after-free error in the 'RenderObject::addChild' function in WebCore/rendering/RenderObject.cpp when handling content around table cells. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2011-10-25
|
WebKit RenderObject::addChild Table Cell Handling Use-after-free Remote Code Execution
|
|
76545
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
|
2011-10-25
|
Google Chrome History Handling URL Bar Spoofing Weakness
|
|
90387
Description:
WebKit contains a flaw in WebCore/page/DOMWindow.cpp as DOMWindow sub-objects can be recreated after navigation. With a specially crafted web page, a context-dependent attacker can bypass the same-origin policy restrictions.
|
2011-10-25
|
WebKit DOMWindow Sub-objects Recreation After Navigation Same Origin Policy Bypass
|
|
90446
Description:
WebKit contains a use-after-free error in the style sheet handling as :before content cannot be properly located in the presence of list markers and run-ins. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2011-10-25
|
WebKit :before Content Location Style Sheet Handling Use-after-free Remote Code Execution
|
|
76642
Description:
(Description Provided by CVE) : Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
|
2011-10-25
|
phpMyFAQ admin/editor/plugins/ajaxfilemanager/ajax_create_folder.php POST Request Parsing Remote PHP Code Execution
|
|
76546
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not properly handle drag and drop operations on URL strings, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
|
2011-10-25
|
Google Chrome Drag and Drop URL Bar Spoofing Weakness
|
|
76547
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not properly handle downloading files that have whitespace characters at the end of a filename, which has unspecified impact and user-assisted remote attack vectors.
|
2011-10-25
|
Google Chrome Download Filename Whitespace Stripping Issue
|
|
76548
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the appcache internals page in Google Chrome before 15.0.874.102 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2011-10-25
|
Google Chrome Appcache Internals Page XSS
|
|
76549
Description:
(Description Provided by CVE) : Race condition in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker process initialization.
|
2011-10-25
|
Google Chrome Worker Process Initialization Unspecified Race Condition Issue
|
|
76550
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not prevent redirects to chrome: URLs, which has unspecified impact and remote attack vectors.
|
2011-10-25
|
Google Chrome Chrome Scheme URI Redirection
|
|
76551
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact and remote attack vectors.
|
2011-10-25
|
Google Chrome HTTP Header Delimiter Unspecified Character Prevention Weakness
|
|
76553
Description:
(Description Provided by CVE) : Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media buffers.
|
2011-10-25
|
Google Chrome Use-after-free Media Buffer Handling Remote Code Execution
|
|
76554
Description:
(Description Provided by CVE) : Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to counters.
|
2011-10-25
|
Google Chrome Use-after-free Counter Handling Remote Code Execution
|
|
76555
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
|
2011-10-25
|
Google Chrome Unspecified DOM Traversal Timing Issue
|
|
76557
Description:
(Description Provided by CVE) : Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers out-of-bounds write operations.
|
2011-10-25
|
Google Chrome v8 Out-of-bounds Write Remote Code Execution
|
|
76558
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
|
2011-10-25
|
Google Chrome Javascript URI Cookie Disclosure
|
|
76559
Description:
(Description Provided by CVE) : Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown plug-in.
|
2011-10-25
|
Google Chrome Use-after-free Plug-ins and Editing Remote Code Execution
|
|
76560
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the Web Audio implementation in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
|
2011-10-25
|
Google Chrome Web Audio Overflow
|
|
76561
Description:
(Description Provided by CVE) : Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video source handling.
|
2011-10-25
|
Google Chrome Use-after-free Video Source Handling Remote Code Execution
|
|
76562
Description:
(Description Provided by CVE) : Google Chrome before 15.0.874.102 does not properly restrict access to internal Google V8 functions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
|
2011-10-25
|
Google Chrome Internal v8 Function Exposure
|
|
77378
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2011-10-25
|
Schneider Electric Multiple Products Unspecified XSS
|
|
76640
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
|
2011-10-25
|
OpenStack Compute (Nova) Invalid Login Parsing EC2_SECRET_KEY Credentials Disclosure
|
|
76637
Description:
Unknown / Incomplete
|
2011-10-25
|
Trend Micro InterScan Web Security Suite setuid/setgid root /opt/trend/iwss/data/patch/bin/patchCmd Multiple Script Local Privilege Escalation
|
|
77444
Description:
(Description Provided by CVE) : The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
|
2011-10-25
|
Apache HTTP Server mod_proxy Mdule Web Request HTTP/0.9 Protocol URL Parsing Proxy Remote Security Bypass
|
|
77490
Description:
(Description Provided by CVE) : Multiple integer overflows in the HTTP server in the Novell XTier framework 3.1.8 allow remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via crafted header length variables.
|
2011-10-25
|
Novell XTier Framework HTTP Server Component Header Parsing Remote Overflow
|
|
77612
Description:
(Description Provided by CVE) : vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.
|
2011-10-25
|
vtiger CRM Leads Module Disabled Field Remote Access Restriction Bypass
|
|
83419
Description:
BlueZone Desktop contains a flaw that may allow for a denial of service. The issue is triggered when a user opens a malformed ZMD file, resulting in a loss of availability for the program. This can be exploited remotely by tricking a user into opening the crafted file (e.g., via email), or locally by placing it in a location that may seem safe (e.g., a network share).
|
2011-10-25
|
BlueZone Desktop .zmd File Handling DoS
|