| OSVDB ID | Disclosure Date | Title |
|
89059
Description:
Oracle Java contains a flaw that allows content combining JMX (Java Management Extensions) MBean components and sun.org.mozilla.javascript.internal objects to call the 'setSecurityManager()' function to elevate privileges. The com.sun.jmx.mbeanserver.MBeanInstantiator.findClass method allows an attacker to retrieve Class references of any package. Using a reflection method (API) recursively, an attacker can then bypass security checks and use this to run privileged code.
|
2013-01-13
|
Oracle Java MBeanInstantiator.findClass Method Remote Code Execution
|
|
75389
Description:
Microsoft SharePoint contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain input in the SharePoint Calender passed via the URL before returning it to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-09-14
|
Microsoft SharePoint SharePoint Calendar URI XSS
|
|
75390
Description:
Microsoft SharePoint contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input upon submission to the EditForm.aspx script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-09-14
|
Microsoft SharePoint EditForm.aspx XSS
|
|
75391
Description:
Microsoft SharePoint contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via contact details before returning it to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-09-14
|
Microsoft SharePoint Contact Details XSS
|
|
75393
Description:
Microsoft SharePoint contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input passed via the URL before returning it to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-09-14
|
Microsoft SharePoint Unspecified URI XSS
|
|
75382
Description:
Microsoft Windows is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a .txt, .rtf or .doc file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2011-09-14
|
Microsoft Windows Shell Extensions Path Subversion Arbitrary DLL Injection Code Execution
|
|
75379
Description:
Microsoft Office is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a .PPT file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2011-09-14
|
Microsoft Office MSO.dll Path Subversion Arbitrary DLL Injection Code Execution
|
|
75383
Description:
(Description Provided by CVE) : Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
|
2011-09-14
|
Microsoft Office Excel Unspecified Use-after-free Memory Dereference Excel File Handling Remote Code Execution
|
|
75384
Description:
(Description Provided by CVE) : Array index error in Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Out of Bounds Array Indexing Vulnerability."
|
2011-09-13
|
Microsoft Office Excel Unspecified Array-Indexing Weakness Excel File Handling Memory Corruption
|
|
75385
Description:
(Description Provided by CVE) : Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly parse records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Heap Corruption Vulnerability."
|
2011-09-13
|
Microsoft Office Excel Unspecified Excel File Record Handling Memory Corruption
|
|
75386
Description:
(Description Provided by CVE) : Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Excel Services on Office SharePoint Server 2007 SP2; Excel Services on Office SharePoint Server 2010 Gold and SP1; and Excel Web App 2010 Gold and SP1 do not properly parse conditional expressions associated with formatting requirements, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Conditional Expression Parsing Vulnerability."
|
2011-09-13
|
Microsoft Office Excel Unspecified Conditional Expression Parsing Excel File Handling Memory Corruption
|
|
75387
Description:
(Description Provided by CVE) : Microsoft Excel 2007 SP2; Excel in Office 2007 SP2; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Excel Services on Office SharePoint Server 2007 SP2 do not properly validate the sign of an unspecified array index, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Out of Bounds Array Indexing Vulnerability."
|
2011-09-13
|
Microsoft Office Excel Unspecified Signedness Error Excel File Handling Memory Corruption
|
|
75380
Description:
(Description Provided by CVE) : Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
|
2011-09-13
|
Microsoft Office MSO.dll Object Pointer Dereference Word Document Handling Remote Code Execution
|
|
75444
Description:
(Description Provided by CVE) : WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."
|
2011-09-13
|
Microsoft Windows WINS Loopback Interface Crafted Packet Local Privilege Escalation
|
|
75381
Description:
(Description Provided by CVE) : Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."
|
2011-09-13
|
Microsoft SharePoint XML / XSL File Handling Unspecified Arbitrary File Disclosure
|
|
75201
Description:
Adobe Flash Player contains a flaw that is triggered when an unspecified error occurs during the handling of SWF files. This may an attacker to execute arbitrary code.
|
2011-08-12
|
Adobe Flash Player SWF File Handling Arbitrary Code Execution (400 Taviso Bugs)
|
|
74408
Description:
Windows Data Access Tracing Component is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a Excel file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2011-08-10
|
Microsoft Windows Data Access Tracing Component Path Subversion Arbitrary DLL Injection Code Execution
|
|
74406
Description:
Microsoft Windows Remote Desktop Web Access contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input to the Logon page before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-08-10
|
Microsoft Windows Remote Desktop Web Access Logon Page Unspecified XSS
|
|
74405
Description:
Microsoft Windows contains a flaw that may allow a remote denial of service. The issue is triggered when the Remote Desktop Protocol fails to properly parse RDP packets, and will result in loss of availability for the platform.
|
2011-08-10
|
Microsoft Windows Remote Desktop Protocol RDP Packet Parsing Remote DoS
|
|
74396
Description:
Microsoft Report Viewer contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input passed to the Microsoft Report Viewer control before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-08-10
|
Microsoft Report Viewer Control Unspecified XSS
|
|
74399
Description:
(Description Provided by CVE) : The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."
|
2011-08-09
|
Microsoft Windows DNS Service NAPTR Query Parsing Overflow
|
|
74400
Description:
(Description Provided by CVE) : The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
|
2011-08-09
|
Microsoft Windows DNS Service Non-Existent Domain Query Parsing Remote DoS
|
|
74403
Description:
(Description Provided by CVE) : The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability."
|
2011-08-09
|
Microsoft .NET Framework Chart Control Special URI Character GET Request Parsing Remote Information Disclosure
|
|
74402
Description:
(Description Provided by CVE) : NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
|
2011-08-09
|
Microsoft Windows Remote Access Service NDISTAPI Driver User Input Validation Weakness Local Privilege Escalation
|
|
74401
Description:
(Description Provided by CVE) : Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Vulnerability."
|
2011-08-09
|
Microsoft Windows Client/Server Run-time Subsystem (CSRSS) Inter-Process Device Event Message Parsing Local Privilege Escalation
|
|
74439
Description:
A memory corruption flaw exists in Adobe Flash Player. The program fails to sanitize user-supplied input, resulting in memory corruption. With a specially crafted file, a context-dependent attacker can execute arbitrary code.
|
2011-08-09
|
Adobe Flash Player MP4 File Handling Memory Corruption (2011-2140)
|
|
74482
Description:
Microsoft Windows contains a flaw that may allow a remote denial of service. The issue is triggered when Tcpip.sys fails to properly parse ICMP messages, and will result in loss of availability for the platform.
|
2011-08-09
|
Microsoft Windows TCP/IP Stack (Tcpip.sys) ICMP Message Parsing Remote DoS
|
|
74483
Description:
Microsoft Windows contains a flaw that may allow a remote denial of service. The issue is triggered when Tcpip.sys fails to properly parse URL requests when URL-based Quality of Service (QoS) is enabled, and will result in loss of availability for the platform.
|
2011-08-09
|
Microsoft Windows TCP/IP Stack (Tcpip.sys) QoS URL Request Parsing Remote DoS
|
|
74495
Description:
A memory corruption flaw exists in Microsoft Internet Explorer. The window.open() function fails to sanitize user-supplied input when the user performs specific sequences of clicks in different IE windows, resulting in memory corruption. With a specially crafted web page or ActiveX control, a context-dependent attacker can execute arbitrary code.
|
2011-08-09
|
Microsoft IE window.open() Function Race Condition Memory Corruption
|
|
74422
Description:
A memory corruption flaw exists in Adobe Photoshop. The program fails to sanitize user-supplied input when handling GIF images, resulting in memory corruption. With a specially crafted GIF image, a context-dependent attacker can execute arbitrary code.
|
2011-08-09
|
Adobe Photoshop GIF Handling Memory Corruption
|
|
74430
Description:
Adobe RoboHelp contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the location.hash DOM property upon submission to the index.html script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-08-09
|
Adobe RoboHelp index.html location.hash DOM Property XSS
|
|
74431
Description:
A memory corruption flaw exists in Adobe Flash Media Server. The program fails to sanitize user-supplied input, resulting in memory corruption. Through unspecified means, a context-dependent attacker can cause a denial of service.
|
2011-08-09
|
Adobe Flash Media Server Unspecified Memory Corruption DoS
|
|
74438
Description:
Adobe Flash Player contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an unspecified error occurs, which will disclose cross-domain information to an attacker.
|
2011-08-09
|
Adobe Flash Player Unspecified Cross-domain Information Disclosure
|
|
74500
Description:
A memory corruption flaw exists in Microsoft Internet Explorer. The program fails to sanitize user-supplied input when an unspecified error occurs during the parsing of objects resulting in memory corruption. This may allow a remote attacker to execute arbitrary code.
|
2011-08-09
|
Microsoft IE STYLE Object Parsing Memory Corruption
|
|
74423
Description:
A memory corruption flaw exists in Adobe Shockwave Player. The program fails to sanitize unspecified user-supplied input, resulting in memory corruption. Through unspecified means, a context-dependent attacker can execute arbitrary code.
|
2011-08-09
|
Adobe Shockwave Player Unspecified Memory Corruption (2010-4308)
|
|
74432
Description:
Adobe Flash Player is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted file, a context-dependent attacker can potentially execute arbitrary code.
|
2011-08-09
|
Adobe Flash Player Unspecified Overflow (2011-2130)
|
|
74424
Description:
A memory corruption flaw exists in Adobe Shockwave Player. The program fails to sanitize unspecified user-supplied input, resulting in memory corruption. Through unspecified means, a context-dependent attacker can execute arbitrary code.
|
2011-08-09
|
Adobe Shockwave Player Unspecified Memory Corruption (2010-4309)
|
|
74425
Description:
A memory corruption flaw exists in Adobe Shockwave Player. The IML32.dll component fails to sanitize unspecified user-supplied input, resulting in memory corruption. Through unspecified means, a context-dependent attacker can execute arbitrary code.
|
2011-08-09
|
Adobe Shockwave Player IML32.dll Unspecified Memory Corruption
|
|
74426
Description:
A memory corruption flaw exists in Adobe Shockwave Player. The program fails to sanitize unspecified user-supplied input, resulting in memory corruption. Through unspecified means, a context-dependent attacker can execute arbitrary code.
|
2011-08-09
|
Adobe Shockwave Player Unspecified Memory Corruption (2011-2420)
|
|
74427
Description:
A memory corruption flaw exists in Adobe Shockwave Player. The Dirapi.dll component fails to sanitize user-supplied input, resulting in memory corruption. With a specially crafted director (.dir) movie file, a context-dependent attacker can execute arbitrary code.
|
2011-08-09
|
Adobe Shockwave Player Dirapi.dll Director Movie File Handling Unspecified Memory Corruption
|