| OSVDB ID | Disclosure Date | Title |
|
79878
Description:
FreeType contains an overflow condition in src/type1/t1load.c. The issue is triggered as user-supplied input is not properly validated during the handling of a loader font dictionary entry. With a specially crafted data in a Type1 font, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2012-02-23
|
FreeType src/type1/t1load.c Type1 Font Loader Font Dictionary Entry Handling Overflow
|
|
80231
Description:
Novell ZENworks Configuration Management is prone to an overflow condition. The PreBoot service fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted 0x6c or 0x4c opscode, a local attacker can potentially cause arbitrary code execution.
|
2012-02-23
|
Novell ZENworks Configuration Management Preboot Service 0x6c / 0x4c Opcode Request Parsing Multiple Unspecified Overflow
|
|
79475
Description:
[PRODUCT] contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the wp-content/plugins/magn-html5-drag-drop-media-uploader/dndupload.phpscript does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
|
2012-02-23
|
Magn Drag and Drop Upload Plugin for WordPress wp-content/plugins/magn-html5-drag-drop-media-uploader/dndupload.php File Upload Remote PHP Code Execution
|
|
79479
Description:
Crop and Square Thumbnails (tkcropthumbs) Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-23
|
Crop and Square Thumbnails (tkcropthumbs) Extension for TYPO3 Unspecified XSS
|
|
79480
Description:
Crop and Square Thumbnails (tkcropthumbs) Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the program not properly sanitizing certain unspecified user-supplied input before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-23
|
Crop and Square Thumbnails (tkcropthumbs) Extension for TYPO3 Unspecified SQL Injection
|
|
79481
Description:
The Typo3 eXtplorer (t3extplorer) contains a flaw that may allows an attacker to traverse outside of a restricted path and possibly access arbitrary files. No further details have been provided.
|
2012-02-23
|
Typo3 eXtplorer (t3extplorer) Extension for TYPO3 Unspecified Traversal Arbitrary File Access
|
|
79482
Description:
TC BE User Admin (tc_beuser) Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-23
|
TC BE User Admin (tc_beuser) Extension for TYPO3 Unspecified XSS
|
|
79483
Description:
Predigtsammlung (an_predigten) Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the program not properly sanitizing certain unspecified user-supplied input before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-23
|
Predigtsammlung (an_predigten) Extension for TYPO3 Unspecified SQL Injection
|
|
79484
Description:
The PDF Controller (pdfcontroller) extension for TYPO3 contains a flaw that may allow an attacker to possibly execute arbitrary code. No further details have been provided.
|
2012-02-23
|
PDF Controller (pdfcontroller) Extension for TYPO3 Unspecified Remote Code Execution
|
|
79485
Description:
The PDF Controller (pdfcontroller) extension for TYPO3 contains a flaw that may allow an attacker to disclose sensitive information. No further details have been provided.
|
2012-02-23
|
PDF Controller (pdfcontroller) Extension for TYPO3 Unspecified Information Disclosure
|
|
79486
Description:
Share Your Car (cc20) Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-23
|
Share Your Car (cc20) Extension for TYPO3 Unspecified XSS
|
|
79487
Description:
Share Your Car (cc20) Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the program not properly sanitizing certain unspecified user-supplied input before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-23
|
Share Your Car (cc20) Extension for TYPO3 Unspecified SQL Injection
|
|
79488
Description:
JW Player (jwplayer) Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-23
|
JW Player (jwplayer) Extension for TYPO3 Unspecified XSS
|
|
79489
Description:
JW Player (jwplayer) Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the program not properly sanitizing certain unspecified user-supplied input before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-23
|
JW Player (jwplayer) Extension for TYPO3 Unspecified SQL Injection
|
|
79509
Description:
The Linux Kernel contains a flaw that may allow a local denial of service. The issue is due to a logical error of the do_traps() function within the software interrupt handler when preemption is enabled, which causes a kernel panic resulting in a loss of availability.
|
2012-02-23
|
Linux Kernel Software Interrupt Handler do_traps() Function CPU Debug Stack Corruption Local DoS
|
|
79505
Description:
The Cisco Small Business SRP520 / SRP540 series contain a flaw related to the web management interface. The issue is due to the application not validating certain HTTP requests which may allow a remote attacker to execute arbitrary commands.
|
2012-02-23
|
Cisco Small Business SRP520 / SRP540 Series Web Interface HTTP Request Parsing Remote Command Execution
|
|
79492
Description:
Csound is prone to an overflow condition. The getnum() function in util/pv_import.c fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted PVOC file, a context-dependent attacker can potentially execute arbitrary code.
|
2012-02-23
|
Csound util/pv_import.c getnum() Function PVOC File Handling Remote Overflow
|
|
79506
Description:
The Cisco Small Business SRP520 / SRP540 series contain a flaw related to authentication management. The issue is due to the application not providing authentication checks when processing certain web requests, which may allow a remote attacker to upload arbitrary configuration files.
|
2012-02-23
|
Cisco Small Business SRP520 / SRP540 Series Missing Authentication Check Web Request Parsing Configuration File Upload
|
|
79643
Description:
The Cookpad and Cookpad Noseru application for Android contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered due to an unspecified error within the WebView class, which will disclose information contained in the application to a remote attacker.
|
2012-02-23
|
Cookpad Noseru Application for Android Unspecified Information Disclosure
|
|
79654
Description:
Kadu contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via SMS or user status messages before returning it for the viewing of a user in the chat history. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-23
|
Kadu Chat History Multiple Message XSS
|
|
79873
Description:
FreeType contains an overflow condition in src/bdf/bdflib.c. The issue is triggered as user-supplied input is not properly validated. With a specially crafted glyph or bitmap information in a BDF font, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2012-02-23
|
FreeType src/bdf/bdflib.c Glyph Information / Bitmaps BDF Font File Handling Overflow
|
|
79874
Description:
FreeType contains a flaw in src/truetype/ttinterp.c that may allow a remote denial of service. The issue is triggered when a NULL pointer dereference occurs in the Zone2 pointer. With a specially crafted TrueType font file, a context-dependent attacker can cause a loss of availability for the program.
|
2012-02-23
|
FreeType src/truetype/ttinterp.c Zone2 Pointer NULL Pointer Dereference TrueType Font Handling Remote DoS
|
|
79876
Description:
FreeType contains an overflow condition in src/pcf/pcfread.c. The issue is triggered as user-supplied input is not properly validated when loading properties. With a specially crafted PFC font, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2012-02-23
|
FreeType src/pcf/pcfread.c Properties Loading PCF Font Handling Overflow
|
|
79877
Description:
FreeType contains an overflow condition in src/smooth/ftsmooth.c. The issue is triggered as user-supplied input is not properly validated. With a specially crafted cell table recording, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2012-02-23
|
FreeType src/smooth/ftsmooth.c Cell Table Recording Buffer Overflow
|
|
79880
Description:
FreeType contains an overflow condition in src/bdf/bdflib.c. The issue is triggered as user-supplied input is not properly validated. With a specially crafted glyph or bitmap information in a BDF font, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2012-02-23
|
FreeType src/bdf/bdflib.c BDF Glyph Information / Bitmap Handling Overflow
|
|
79881
Description:
FreeType contains an overflow condition in src/type1/t1parse.c. The issue is triggered as user-supplied input is not properly validated. With a specially crafted private-dictionary data in a Type 1 font, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2012-02-23
|
FreeType src/type1/t1parse.c Type1 Font Parser Font Private Dictionary Retrieval Overflow
|
|
79446
Description:
SB Uploader Plugin for WordPress contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the wp-content/plugins/sb-uploader/sb_uploader.php script does not properly verify uploaded files. This may allow a user to create a specially crafted PHP script that would execute arbitrary PHP code when uploaded.
|
2012-02-23
|
SB Uploader Plugin for WordPress wp-content/plugins/sb-uploader/sb_uploader.php File Upload Remote PHP Code Execution
|
|
79458
Description:
SocialCMS Enterprise contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'search.php' script not properly sanitizing user-supplied input to the 'category' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-23
|
SocialCMS Enterprise search.php category Parameter SQL Injection
|
|
79490
Description:
Elefant CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the apps/admin/handlers/preview.php script does not validate the 'layout', 'title', 'window_title' and 'body' parameters upon submission to the admin/preview script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-23
|
Elefant CMS apps/admin/handlers/preview.php Multiple Parameter XSS
|
|
79470
Description:
Movable Type contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'dbuser' parameter upon submission to the '/cgi-bin/mt/mt-wizard.cgi' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-23
|
Movable Type /cgi-bin/mt/mt-wizard.cgi dbuser Parameter XSS
|
|
79471
Description:
Movable Type contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate user-supplied input upon submission to various unspecified templates. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-23
|
Movable Type Templates Unspecified XSS
|
|
79672
Description:
Linux Kernel contains a flaw in the Common Internet File System (CIFS) component that may allow a local denial of service. The issue is due to an error in the cifs_lookup function in fs/cifs/dir.c. With an attempted access to a samba share, a local attacker can crash the systems of users that have access to the same samba share.
|
2012-02-23
|
Linux Kernel CIFS FIFO File Handling Local DoS
|
|
80765
Description:
PTK Forensics contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions of the /lib/logout.php script. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into forcing administrators to logout in the context of their session with the application, without further prompting or verification.
|
2012-02-23
|
PTK Forensics /lib/logout.php Admin Forced Logout CSRF
|
|
87732
Description:
Front End User Registration (sr_feuser_register) Extension for TYPO3 contains a flaw that may lead to an unauthorized information disclosure. The issue is due to user password information being stored in cleartext. This may allow a remote attacker to gain access to user password information via the edit prespective.
|
2012-02-23
|
Front End User Registration (sr_feuser_register) Extension for TYPO3 Edit Perspective Cleartext User Password Disclosure
|
|
87731
Description:
Front End User Registration (sr_feuser_register) Extension for TYPO3 contains a flaw that may lead to an unauthorized information disclosure. The issue is due to user password information being stored in plaintext, and being sent via GET request during a redirect after autologin.
|
2012-02-23
|
Front End User Registration (sr_feuser_register) Extension for TYPO3 Autologin Redirect Cleartext Credential Disclosure
|
|
91172
Description:
Apache Wicket contains a flaw that is triggered when appending a URL with %10, %13, or %20. This may allow a remote attacker to bypass the file extension filters in the PackageResourceGuard functionality.
|
2012-02-23
|
Apache Wicket PackageResourceGuard File Extension Filter Bypass
|
|
79455
Description:
Chyrp contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'body' parameter upon submission to the includes/error.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-22
|
Chyrp includes/error.php body Parameter XSS
|
|
79457
Description:
SocialCMS Enterprise contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the ' TR_name' parameter upon submission to the 'ajax/commentajax.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-22
|
SocialCMS Enterprise ajax/commentajax.php TR_name Parameter XSS
|
|
79466
Description:
The FAQ module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'title' parameter upon submission to faq.admin.inc. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-22
|
FAQ Module for Drupal faq.admin.inc title Parameter XSS
|
|
79468
Description:
OneForum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the topic.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-22
|
OneForum topic.php id Parameter SQL Injection
|