| OSVDB ID | Disclosure Date | Title |
|
78366
Description:
Quick Tabs Module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input when creating or editing tabbed content before returning it to the uesr. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-18
|
Quick Tabs Module for Drupal Tabbed Content Manipulation XSS
|
|
78367
Description:
Panels contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the title field when creating customized layouts. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-18
|
Panels Module for Drupal Customised Layout Region Creation Region Title Field XSS
|
|
78322
Description:
By default, Cisco TelePresence System installs with a default password. The root account, which is not properly disabled when an admin attempts to deactivate it, has a password which is publicly known and documented. This allows attackers to trivially access the program or system and gain privileged access.
|
2012-01-18
|
Cisco TelePresence System Hardcoded Default Root Account
|
|
78413
Description:
Oracle Virtual Desktop Infrastructure contains a flaw related to the Session component that may allow a remote attacker to manipulate certain unspecified data and gain unauthorized access to certain unspecified information. No further details have been provided.
|
2012-01-18
|
Oracle Virtual Desktop Infrastructure Session Component Unspecified Remote Issue
|
|
78477
Description:
Horde IMP contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate user-supplied input via IMAP mailbox names. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-18
|
Horde IMP IMAP Mailbox Name XSS
|
|
78608
Description:
Adobe Reader for Linux is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in an overflow. This may allow an attacker to potentially execute arbitrary code or cause a denial of service.
|
2012-01-18
|
Adobe Reader for Linux Unspecified Overflow
|
|
82526
Description:
PhpBridges contains a flaw related to the blog system that may allow an attacker to carry out an SQL injection attack. The issue is due to the members.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-01-18
|
PhpBridges Blog System members.php id Parameter SQL Injection
|
|
82709
Description:
OneOrZero Action and Information Management System(AIMS) contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the PATH_INFO parameter (URL) before using it in the index.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-18
|
OneOrZero Action & Information Management System (AIMS) index.php PATH_INFO Parameter XSS
|
|
86233
Description:
Mingle Forum Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the fs-admin/fs-admin.php script not properly sanitizing user-supplied input to the 'id', 'delete_usrgrp[]', 'usergroup', and 'add_forum_group_id' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-01-18
|
Mingle Forum Plugin for WordPress fs-admin/fs-admin.php Multiple Parameter SQL Injection
|
|
78347
Description:
Moodle contains a flaw in the handling of e-mail headers. The issue is due to the application not properly sanitizing user-supplied input when creating e-mail messages. With a specially crafted request, a remote attacker can potentially inject arbitrary e-mail headers.
|
2012-01-18
|
Moodle Unspecified Email Header Injection
|
|
78349
Description:
Moodle contains a flaw that leads to unauthorized privileges being gained. The issue is due to an error within the course self-enrollment feature and may allow a remote attacker to gain manager privileges.
|
2012-01-18
|
Moodle Self-Enrolment Feature Manager Privilege Escalation
|
|
78475
Description:
Horde IMP contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'composeCache', 'rtemode', and 'filename_*' parameters upon submission to the compose page. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-18
|
Horde IMP Compose Page Multiple Parameter XSS
|
|
78448
Description:
EasyPage EV10 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the default.aspx script not properly sanitizing user-supplied input to the 'docId' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-01-18
|
EasyPage EV10 default.aspx docId Parameter SQL Injection
|
|
78476
Description:
Horde IMP contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'formname' parameter upon submission to the Contacts pop-up window. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-18
|
Horde IMP Contacts Popup Window formname Parameter XSS
|
|
78573
Description:
Apache Tomcat contains a flaw in the handling of parameters that may allow a remote denial of service. The issue is due to an error when handling requests containing many parameters and parameter values. With a specially crafted request, a remote attacker can cause the service to exhaust all available CPU.
|
2012-01-18
|
Apache Tomcat Parameter Saturation CPU Consumption Remote DoS
|
|
78704
Description:
JBoss Enterprise Web Server contains a flaw in the mod_cluster component. The issue is due to the application not properly enforcing security controls, which may allow a remote attacker to bypass access restrictions when registering worker nodes with arbitrary virtual hosts.
|
2012-01-18
|
JBoss Enterprise Web Server mod_cluster Virtual Host Registration Access Restriction Bypass
|
|
89733
Description:
Freelance Zone contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the show_code.php script not properly sanitizing user-supplied input to the 'code_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-01-18
|
Freelance Zone show_code.php code_id Parameter SQL Injection
|
|
78353
Description:
Multiple Rockwell Automation products contain a flaw in the FactoryTalk Diagnostics CE Receiver service (RNADiagReceiver.exe) that may allow a remote denial of service. The issue is triggered when receiving a datagram larger than 2000 bytes. With a specially crafted request, a remote attacker can cause the service to silently stop processing new, incoming requests.
|
2012-01-17
|
Rockwell Automation FactoryTalk Diagnostics Receiver Service RNADiagReceiver.exe Overly Large Datagram Parsing Remote DoS
|
|
78474
Description:
Horde Groupware Webmail Edition contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the input passed to Horde_Form related to email verification before being returned to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-17
|
Horde Groupware Webmail Edition Horde_Form Email Verification XSS
|
|
78509
Description:
Linux Kernel contains a flaw that leads to unauthorized privileges being gained. The issue is due to the mem_write function not properly validating permissions when writing to /proc/<pid>/mem and may allow a local attacker to gain privileges by modifying process memory.
|
2012-01-17
|
Linux Kernel /proc/<pid>/mem Access Restriction Weakness Local Privilege Escalation
|
|
78411
Description:
Oracle Outside In Technology contains a flaw related to the Lotus 123 v4 Parser that may allow a remote attacker to execute arbitrary code. No further details have been provided.
|
2012-01-17
|
Oracle Outside In Technology Lotus 123 v4 Parser vswk4.dll Unspecified Remote Code Execution
|
|
78356
Description:
XnView is prone to an overflow condition. The program fails to properly parse PSD record types resulting in a integer overflow. With a specially crafted PSD image, a remote attacker can potentially cause arbitrary code execution.
|
2012-01-17
|
XnView PSD Record Type Image Handling Remote Overflow (2012-0684)
|
|
78374
Description:
Oracle MySQL Server contains an unspecified flaw related to the MySQL Protocol that may allow a remote attacker to cause a loss of integrity.
|
2012-01-17
|
Oracle MySQL Server Unspecified Remote Issue (2012-0075)
|
|
78420
Description:
Oracle Solaris contains a flaw that may allow a remote denial of service. The issue is triggered when an unspecified error in the TCP/IP component is exploited, and will result in a loss of availability.
|
2012-01-17
|
Oracle Solaris TCP/IP Component Unspecified Remote DoS
|
|
78415
Description:
Oracle GlassFish Enterprise Server contains a flaw related to the Administration component that may allow a local attacker to affect confidentiality, integrity and availability. No further details have been provided.
|
2012-01-17
|
Oracle GlassFish Enterprise Server Administration Component Unspecified Local Issue
|
|
78421
Description:
Oracle Solaris contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an unspecified error in the Kerberos component is exploited, allowing a local attacker to gain elevated privileges.
|
2012-01-17
|
Oracle Solaris Kerberos Component Unspecified Local Privilege Escalation
|
|
78422
Description:
Oracle Solaris contains a flaw that may allow a remote denial of service. The issue is triggered when an unspecified error in the Network component is exploited, and will result in a loss of availability.
|
2012-01-17
|
Oracle Solaris Network Component Unspecified Remote DoS
|
|
78423
Description:
Oracle Solaris contains a flaw that may allow a local denial of service. The issue is triggered when an unspecified error in the Kernel component is exploited, and will result in a loss of availability.
|
2012-01-17
|
Oracle Solaris Kernel Component Unspecified Local DoS (2012-0103)
|
|
78424
Description:
Oracle Solaris contains an unspecified flaw related to the TCP/IP component that may allow a local attacker to affect confidentiality and availability. No further details have been provided.
|
2012-01-17
|
Oracle Solaris TCP/IP Component Unspecified Local Issue
|
|
78425
Description:
Oracle Solaris contains a flaw that may allow a remote denial of service. The issue is triggered when an unspecified error in the sshd component is exploited, and will result in a loss of availability.
|
2012-01-17
|
Oracle Solaris sshd Component Unspecified Remote DoS
|
|
78426
Description:
Oracle Solaris contains a flaw that may allow a local information disclosure. The issue is triggered when an unspecified error in the ksh93 Shell component is exploited, and will result in a loss of confidentiality.
|
2012-01-17
|
Oracle Solaris ksh93 Shell Component Unspecified Local Information Disclosure
|
|
78427
Description:
Oracle Solaris contains a flaw that may allow a local denial of service. The issue is triggered when an unspecified error in the kernel component is exploited, and will result in a loss of availability.
|
2012-01-17
|
Oracle Solaris Kernel Component Unspecified Local DoS (2012-0098)
|
|
78433
Description:
Oracle JD Edwards EnterpriseOne Tools contains a flaw related to the Enterprise Infrastructure SEC (JDENET) sub-component that may allow a remote authenticated attacker to gain unauthorized access to certain user password information via a specially crafted packet.
|
2012-01-17
|
Oracle JD Edwards EnterpriseOne Tools JDENET Crafted Packet Arbitrary User Password Remote Disclosure
|
|
78435
Description:
Oracle JD Edwards EnterpriseOne Tools contains a flaw related to the Enterprise Infrastructure SEC (JDENET) sub-component that is triggered during the handling of a specially crafted packet. This may allow a remote authenticated attacker to gain access to arbitrary files.
|
2012-01-17
|
Oracle JD Edwards EnterpriseOne Tools JDENET Crafted Packet Arbitrary File Remote Disclosure
|
|
78437
Description:
Oracle JD Edwards EnterpriseOne Tools contains a flaw related to the Enterprise Infrastructure SEC (JDENET) sub-component. This issue is triggered during the handling of a specially crafted request, which may allow a remote authenticated attacker to gain access to content located in the JDE.INI file.
|
2012-01-17
|
Oracle JD Edwards EnterpriseOne Tools JDENET Crafted Request JDE.INI File Content Remote Disclosure
|
|
78438
Description:
Oracle JD Edwards EnterpriseOne Tools contains a flaw related to the Enterprise Infrastructure SEC (JDENET) sub-component that is triggered during the handling of message file packets. This may allow a remote authenticated attacker to overwrite arbitrary files.
|
2012-01-17
|
Oracle JD Edwards EnterpriseOne Tools JDENET Message File Packet Handling Arbitrary File Manipulation
|
|
78442
Description:
Oracle VM VirtualBox contains a flaw related to the Windows Guest Additions component that may allow a local attacker to affect confidentiality, integrity and availability. No further details have been provided.
|
2012-01-17
|
Oracle VM VirtualBox Windows Guest Additions Component Unspecified Local Issue
|
|
78471
Description:
EMC SourceOne Email Management contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to the web search component logging authentication information in clear text in the web server log and may disclose user credentials to a remote attacker.
|
2012-01-17
|
EMC SourceOne Email Management Cleartext Credentials Disclosure
|
|
78472
Description:
GoLismero contains a flaw that may allow a malicious local user to overwrite arbitrary files on the system. The issue is due to the GoLismero creating temporary files insecurely. It is possible for a local attacker to use a symlink attack to cause the software to operate on unauthorized files and overwrite arbitrary files owned by user.
|
2012-01-17
|
GoLISMERO /lib/updater.py Symlink Arbitrary File Overwrite
|
|
79394
Description:
Tiki Wiki CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-17
|
Tiki Wiki CMS Unspecified XSS
|