| OSVDB ID | Disclosure Date | Title |
|
79685
Description:
Hitachi JP1/Cm2/Network Node Manager contains multiple flaws that may allow an attacker to possibly execute arbitrary code. No further details have been provided.
|
2012-02-29
|
Hitachi JP1/Cm2/Network Node Manager Multiple Unspecified Remote Code Execution
|
|
79693
Description:
Cisco Cius contains a flaw that may allow a remote denial of service. The issue is triggered when handling malformed packets which causes the device to stop responding resulting in a loss of availability.
|
2012-02-29
|
Cisco Cius Incoming Traffic Packet Parsing Remote DoS
|
|
79696
Description:
Submenu Tree Module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input when editing menus before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-29
|
Submenu Tree Module for Drupal Menu Editing Unspecified XSS
|
|
79680
Description:
Traidnt Topics Viewer contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the main.php script does not require multiple steps or explicit confirmation for sensitive transactions for the addition of administrator users. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2012-02-29
|
Traidnt Topics Viewer main.php Admin User Creation CSRF
|
|
79681
Description:
file libmagic contains a flaw that may allow a remote denial of service. The issue is triggered by an error when handling malformed CDF files, and will result in loss of availability for the program.
|
2012-02-29
|
file libmagic CDF File Handling Remote DoS
|
|
79682
Description:
Taxonomy Views Integrator Module for Drupal contains a flaw related to viewing pages that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-29
|
Taxonomy Views Integrator Module for Drupal Views Pages Unspecified XSS
|
|
79683
Description:
The Hierarchical Select Module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate help text upon submission to vocabularies. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-29
|
Hierarchical Select Module for Drupal Vocabulary Help Text XSS
|
|
79684
Description:
The MediaFront Module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the '$_SESSION' and '$_SERVER' variables upon submission to the MediaFront module. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-29
|
MediaFront Module for Drupal PHP Library Multiple Parameter XSS
|
|
79686
Description:
Hitachi JP1/Cm2/Network Node Manager contains a flaw that may allow a remote denial of service. The issue is triggered due to multiple unspecified issues. No further details have been provided.
|
2012-02-29
|
Hitachi JP1/Cm2/Network Node Manager Multiple Unspecified Remote DoS
|
|
79706
Description:
Cisco Unified Communications Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the application not properly sanitizing user-supplied input to Skinny Client Control Protocol (SCCP) messages. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-29
|
Cisco Unified Communications Manager SCCP Registration Message SQL Injection
|
|
79709
Description:
Cisco Unity Connection (UC) contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is due to a flaw within the assignment and validation of privileges which may allow a remote attacker to change the administrator password.
|
2012-02-29
|
Cisco Unity Connection (UC) Help Desk Administrator Role Admin Password Manipulation
|
|
79721
Description:
Kingsoft Antivirus contains a flaw that may allow a local denial of service. The issue is due to an unspecified error within the 'knetwch.sys' device driver and the handling of device-specific operations, resulting in a loss of availability for the program.
|
2012-02-29
|
Kingsoft Antivirus 2011 knetwch.sys IOCTL Parsing Unspecified Local DoS
|
|
79710
Description:
Cisco Unity Connection contains a flaw that may allow a remote denial of service. The issue is triggered when sending TCP segments with an arbitrary size, and will result in loss of availability for certain system services.
|
2012-02-29
|
Cisco Unity Connection TCP Segment Parsing Remote DoS
|
|
79716
Description:
NetEase CloudAlbum for Android contains an unspecified flaw that may allow an attacker to have an unspecified impact. No further details have been provided.
|
2012-02-29
|
NetEase CloudAlbum (com.netease.cloudalbum) Application for Android Unspecified Issue
|
|
79740
Description:
BrewBlogger contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the index.php script does not properly verify or sanitize user-uploaded files. By uploading a file of an unspecified type, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute it.
|
2012-02-29
|
BrewBlogger index.php Arbitrary File Upload
|
|
79766
Description:
The ZipCart Module for Drupal contains a flaw related to the assignment of incorrect permissions when building archives, which may allow an attacker to bypass certain access restrictions.
|
2012-02-29
|
ZipCart Module for Drupal Archive Building Access Restriction Bypass
|
|
79741
Description:
BrewBlogger contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the includes/upload_image.inc.php script does not properly verify or sanitize user-uploaded files. By uploading a file of an unspecified type, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute it.
|
2012-02-29
|
BrewBlogger includes/upload_image.inc.php Arbitrary File Upload
|
|
79742
Description:
BrewBlogger contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the index.php script does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of administrator's passwords. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2012-02-29
|
BrewBlogger index.php Admin Password Manipulation CSRF
|
|
79772
Description:
The Cool Aid Module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate user-supplied input upon submission to certain unspecified scripts. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-29
|
Cool Aid Module for Drupal Unspecified Access Restriction Bypass
|
|
80097
Description:
WebCalendar contains a flaw related to the install/index.php script which may allows a remote attacker to overwrite settings.php with arbitrary data when saving a user theme preference.
|
2012-02-29
|
WebCalendar install/index.php User Theme Preference Save settings.php Overwrite
|
|
89277
Description:
By default, NETGEAR DGN1000 and DGND3700 routers install with default user credentials (username/password combination). The 'admin' account has a password of 'password', which is publicly known and documented. This allows remote attackers to trivially access the program or system and gain privileged access. In addition, the DGND3700 installs with a 'guest' account that has a password of 'guest'.
|
2012-02-29
|
NETGEAR Multiple Router Admin Interface Default Credentials
|
|
79658
Description:
Webfolio CMS contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the creation of an administrator level user or the editing of certain pages. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2012-02-29
|
Webfolio CMS Admin User Creation CSRF
|
|
79659
Description:
Anchor CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'real_name' parameter upon submission to the index.php/admin/users/edit/2 script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-29
|
Anchor CMS index.php/admin/users/edit/2 real_name Parameter XSS
|
|
79670
Description:
ImgPals Photo Host contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the approve.php script not properly sanitizing user-supplied input to the 'u' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-29
|
ImgPals Photo Host approve.php u Parameter SQL Injection
|
|
79695
Description:
GNOME NetworkManager contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when creating new connections and specifying arbitrary file names, which may allow a local attacker to gain access to arbitrary files.
|
2012-02-29
|
GNOME NetworkManager Local Arbitrary File Access
|
|
79701
Description:
The Youdao Dictionary Application for Android contains an unspecified flaw that may allow an attacker to conduct an attack with unknown impact. No further details have been provided.
|
2012-02-29
|
Youdao Dictionary Application for Android Unspecified Issue
|
|
79713
Description:
Cisco TelePresence Video Communication Server contains a flaw that may allow a remote denial of service. The issue is triggered when sending specially crafted SIP packets, which causes the server to crash resulting in a loss of availability.
|
2012-02-29
|
Cisco TelePresence Video Communication Server SIP Packet Parsing Remote DoS
|
|
79707
Description:
Cisco Unified Communications Manager contains a flaw that may allow a remote denial of service. The issue is triggered when sending specially crafted Skinny Client Control Protocol (SCCP) messages, which causes the device to reload resulting in a loss of availability.
|
2012-02-29
|
Cisco Unified Communications Manager SCCP Registration Message Parsing Remote DoS
|
|
79714
Description:
Cisco TelePresence Video Communication Server contains a flaw that may allow a remote denial of service. The issue is triggered when sending specially crafted SIP INVITE messages, which causes the server to crash resulting in a loss of availability.
|
2012-02-29
|
Cisco TelePresence Video Communication Server SIP INVITE Message Parsing Remote DoS
|
|
86215
Description:
WebCalendar contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the '$url', '$tempfullname', and '$ext_users[]' parameters upon submission to the view_entry.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-29
|
WebCalendar view_entry.php Multiple Parameter XSS
|
|
90053
Description:
CHICKEN on 64-bit systems contains a flaw that is due to the randomization feature incorrectly returning a constant value multiple times. While the randomization procedure is not intended for secure entropy generation, the function may be used for it. In such cases, any routine or functionality that relies on random output may be compromised.
|
2012-02-29
|
CHICKEN on 64-bit Randomization Procedure Constant Value Weakness
|
|
79657
Description:
IBM Personal Communications is prone to an overflow condition. The 'pcspref.dll' library fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted WorkStation Profile file (.ws), a context-dependent attacker can potentially execute arbitrary code.
|
2012-02-29
|
IBM Personal Communications pcspref.dll WorkStation Profile .ws File Handling Remote Overflow
|
|
79671
Description:
Drupal contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an error message is displayed due to an excess of database connections, which will disclose the database and username as configured in settings.php to a remote attacker.
|
2012-02-29
|
Drupal Error Message Database / Username Remote Disclosure
|
|
79676
Description:
The Cisco Wireless LAN Controller contains a flaw that may allow a remote denial of service. The issue is triggered when sending a specially crafted URL to the administrative management interface which causes the device to crash resulting in a loss of availability.
|
2012-02-29
|
Cisco Wireless LAN Controllers (WLC) Administrative Management Interface URL Parsing Remote DoS
|
|
79677
Description:
The Cisco Wireless LAN Controller contains a flaw that may allow a remote denial of service. The issue is triggered when sending specially crafted IPv6 packets which cause the device to reboot resulting in a loss of availability.
|
2012-02-29
|
Cisco Wireless LAN Controllers (WLC) IPv6 Packet Parsing Remote DoS
|
|
79678
Description:
The Cisco Wireless LAN Controller contains a flaw that may allow a remote denial of service. The issue is triggered when WebAuth is enabled and specially crafted HTTP or HTTPS packets are sent to the interface, which cause the device to reboot resulting in a loss of availability.
|
2012-02-29
|
Cisco Wireless LAN Controllers (WLC) WebAuth HTTP/HTTPS Packet Parsing Remote DoS
|
|
79679
Description:
The Cisco Wireless LAN Controller contains a flaw related to the ACL functionality. The issue is triggered when CPU-based ACLs are enabled. This may allow an attacker to view or manipulate arbitrary configuration settings. No further details have been provided.
|
2012-02-29
|
Cisco Wireless LAN Controllers (WLC) CPU Access Control List Configuration Manipulation
|
|
79715
Description:
NetEase Weibo for Android contains an unspecified flaw that may allow an attacker to have an unspecified impact. No further details have been provided.
|
2012-02-29
|
NetEase Weibo (com.netease.wb) Application for Android Unspecified Issue
|
|
79656
Description:
The Linux Kernel contains a flaw that may allow a local denial of service. The issue is due to the 'tomoyo_mount_acl()' function not properly validating mount requests containing a 'NULL' value. With a specially crafted mount request, a local attacker can cause a kernel panic resulting in a loss of availability.
|
2012-02-28
|
Linux Kernel TOMOYO LSM Mount System Call Handling Local DoS
|
|
85781
Description:
Fork CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'term' parameter upon submission to the save.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-28
|
Fork CMS save.php term Parameter XSS
|