| OSVDB ID | Disclosure Date | Title |
|
74501
Description:
PHP-Nuke contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'sender_name' and 'sender_email' parameters upon submission to the Feedback module. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-23
|
PHP-Nuke Feedback Module Multiple Parameter XSS
|
|
75067
Description:
Unknown / Incomplete
|
2011-03-23
|
Achievo Scheduler Module owner Parameter Arbitrary Schedule Addition
|
|
75068
Description:
Achievo contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the include.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'node' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-03-23
|
Achievo include.php node Parameter Traversal Local File Inclusion
|
|
75069
Description:
Achievo contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the graph.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'plotter' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-03-23
|
Achievo graph.php plotter Parameter Traversal Local File Inclusion
|
|
75070
Description:
Achievo contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the graph.php script not properly sanitizing user-supplied input to the 'viewstart' and 'viewend' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-23
|
Achievo graph.php Multiple Parameter SQL Injection
|
|
75259
Description:
(Description Provided by CVE) : SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root filesystem operations by the Cobbler daemon.
|
2011-03-23
|
SUSE openSUSE Factory /var/log/cobbler/ Local Privilege Escalation
|
|
75355
Description:
Unknown / Incomplete
|
2011-03-23
|
Joomla! libraries/phpmailer/language/phpmailer.lang-joomla.php Direct Request Path Disclosure
|
|
76075
Description:
(Description Provided by CVE) : The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.
|
2011-03-23
|
IBM AIX QLogic Adapter DMA Resource Weakness Local DoS
|
|
71639
Description:
(Description Provided by CVE) : The plug-in in QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via vectors involving a cross-site redirect.
|
2011-03-22
|
Apple Mac OS X QuickTime Cross-site Redirect Cross-domain Information Disclosure
|
|
71279
Description:
Loggerhead contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input related to the filename is in loggerhead/templatefunctions.py script before being displayed in revision view filenames. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-22
|
Loggerhead loggerhead/templatefunctions.py Revision View Filename XSS
|
|
74630
Description:
(Description Provided by CVE) : The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
|
2011-03-22
|
tex-common conf/texmf.d/95NonPath.cnf shell_escape_commands Directive Crafted TeX Document Remote Code Execution
|
|
71653
Description:
(Description Provided by CVE) : kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.
|
2011-03-22
|
Linux Kernel rt_*sigqueueinfo() Functions SI_TKILL Signal Spoofing
|
|
71626
Description:
(Description Provided by CVE) : AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162.
|
2011-03-22
|
Apple Mac OS X AirPort Wi-Fi Frame Handling Divide-by-zero Remote DoS
|
|
71627
Description:
(Description Provided by CVE) : Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio application.
|
2011-03-22
|
Apple Mac OS X AppleScript Generic Dialog Commands Format String
|
|
71628
Description:
(Description Provided by CVE) : Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.
|
2011-03-22
|
Apple Mac OS X ATS OpenType Font Handling Overflow
|
|
71629
Description:
(Description Provided by CVE) : Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded TrueType font.
|
2011-03-22
|
Apple Mac OS X ATS TrueType Font Handling Multiple Overflows
|
|
71630
Description:
(Description Provided by CVE) : Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font.
|
2011-03-22
|
Apple Mac OS X ATS Type 1 Font Handling Multiple Overflows
|
|
71631
Description:
(Description Provided by CVE) : Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font.
|
2011-03-22
|
Apple Mac OS X ATS SFNT Table Handling Multiple Overflows
|
|
71632
Description:
(Description Provided by CVE) : The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.
|
2011-03-22
|
Apple Mac OS X CarbonCore FSFindFolder() API Returned Directory Permission Weakness
|
|
71633
Description:
(Description Provided by CVE) : CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font.
|
2011-03-22
|
Apple Mac OS X CoreText Font File Handling Memory Corruption
|
|
71634
Description:
(Description Provided by CVE) : Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.
|
2011-03-22
|
Apple Mac OS X HFS F_READBOOTSTRAP Ioctl Overflow Information Disclosure
|
|
71636
Description:
(Description Provided by CVE) : Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an NFS RPC packet, which allows remote attackers to cause a denial of service (lockd, statd, mountd, or portmap outage) via a crafted packet, related to an "integer truncation issue."
|
2011-03-22
|
Apple Mac OS X Libinfo NFS RPC Packet Handling Remote DoS
|
|
71638
Description:
(Description Provided by CVE) : QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG2000 image.
|
2011-03-22
|
Apple Mac OS X QuickTime JPEG2000 Image Handling Memory Corruption
|
|
71640
Description:
(Description Provided by CVE) : The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."
|
2011-03-22
|
Apple Mac OS X Ruby BigDecimal Class Integer Truncation Arbitrary Code Execution
|
|
71641
Description:
(Description Provided by CVE) : The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attackers to spoof SSH servers by leveraging protocol vulnerabilities.
|
2011-03-22
|
Apple Mac OS X Terminal New Remote Connection Protocol Reversion Weakness
|
|
71642
Description:
(Description Provided by CVE) : Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server.
|
2011-03-22
|
Apple Mac OS X Installer Helper Arbitrary Agent Installation
|
|
71643
Description:
(Description Provided by CVE) : Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.
|
2011-03-22
|
Apple Mac OS X Canon RAW Image Handling Multiple Overflows
|
|
71644
Description:
(Description Provided by CVE) : Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding.
|
2011-03-22
|
Apple Mac OS X ImageIO JPEG-encoded TIFF Image Handling Overflow
|
|
71262
Description:
Immunity Debugger is prone to an overflow condition. The program fails to properly verify communication with the update server, allowing a remote attacker to use a man-in-the-middle attack to spoof responses containing overly long strings to cause a heap-based buffer overflow. This may allow the execution of arbitrary code.
|
2011-03-22
|
Immunity Debugger Update Server HTTP Response Overflow
|
|
75255
Description:
WebKit contains a flaw as it fails to properly restrict cross-origin drag-and-drop operations that may allow a remote attacker to bypass the Same Origin Policy. With a specially crafted web page, a context-dependent attacker can obtain potentially sensitive information from another web page.
|
2011-03-22
|
WebKit Cross-Origin Drag-and-Drop Frame Handling Information Disclosure Weakness
|
|
71253
Description:
openSUSE contains a flaw related to aaa_base failing to properly handle filenames with meta characters during tab expansions. This may allow a context-dependent attacker to use a crafted filename to trick another user to execute arbitrary commands, which may allow the attacker to gain elevated privileges.
|
2011-03-22
|
openSUSE aaa_base Metacharacter Tab Expansion Filename Handling Command Execution
|
|
71681
Description:
(Description Provided by CVE) : The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physically proximate attackers to perform administrative changes or obtain sensitive information via a (1) Load, (2) Tell, or (3) Set Configuration command.
|
2011-03-22
|
IBM Lotus Domino Server_Console_Password Weakness Authentication Bypass Remote Code Execution
|
|
72868
Description:
CSE-Semaphore TBOX Lite 200 contains a flaw related to the 'tcomm.dll' library. The issue is triggered when a remote attacker supplies a specially crafted VBScript. This may allow an attacker to bypass authentication settings.
|
2011-03-22
|
CSE-Semaphore TBOX LITE 200 tcomm.dll Crafted VBScript Remote Authentication Bypass
|
|
73773
Description:
WebKit contains a flaw that may lead to unauthorized disclosure of sensitive information. The issue is triggered when handling access to local file content. With a specially crafted web page, a context-dependent attacker may disclose the contents of arbitrary local files on a user's system.
|
2011-03-22
|
WebKit Windows Functionality Same Origin Policy Bypass Arbitrary File Disclosure
|
|
74757
Description:
libpng contains a flaw in the handling of JPG files that may allow a remote denial of service. The issue is due to an error of the embedded_profile_len() function in pngwutil.c. With a specially crafted JPG file containing an iCCP chunk with a negative embedded profile length, a context-dependent attacker can cause the program to crash.
|
2011-03-22
|
libpng iCCP Chunk Embedded Profile Length Verification JPG Image Handling Remote DoS
|
|
71259
Description:
Quagga contains a flaw that may allow a remote denial of service. The issue is triggered when a NULL-pointer dereference error occurs, allowing a remote attacker to use crafted extended community attributes to crash the 'bgpd' daemon, resulting in a loss of availability.
|
2011-03-22
|
Quagga Extended Communities Attribute Handling NULL Dereference Remote DoS
|
|
71258
Description:
Quagga contains a flaw that may allow a remote denial of service. The issue is triggered when the AS path limit/TTL functionality encounters an error when parsing some specific AS_PATHLIMIT attributes, allowing a remote attacker to use crafted AS_PATHLIMIT attributes to reset BGP sessions, resulting in a loss of availability.
|
2011-03-22
|
Quagga AS_PATHLIMIT BGP Session Reset Remote DoS
|
|
71260
Description:
RealPlayer is prone to an overflow condition. rvrender.dll fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted .IVR file, a context-dependent attacker can potentially execute arbitrary code.
|
2011-03-22
|
RealPlayer rvrender.dll IVR File Handling Overflow
|
|
71261
Description:
Symantec LiveUpdate Administrator contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the execution of arbitrary commands, creation of administrative users, or insertion of scripts. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-03-22
|
Symantec LiveUpdate Administrator Multiple Admin Function CSRF
|
|
75055
Description:
(Description Provided by CVE) : The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.
|
2011-03-22
|
Nokia E75 Device Lock Code Bypass
|