| OSVDB ID | Disclosure Date | Title |
|
70702
Description:
Bugzilla contains a flaw in the duplicate-detection functionality that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'summary' field before returning it to the user, due to the YUI DataTable widget's rendering of strings as text. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-01-24
|
Bugzilla YUI DataTable Widget Duplicate Detection Summary Field XSS
|
|
70705
Description:
Bugzilla contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the 'buglist.cgi' script does not require multiple steps or explicit confirmation for sensitive transactions for the addition of saved searches to a user's profile. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-01-24
|
Bugzilla buglist.cgi Saved Search Addition CSRF
|
|
70706
Description:
Bugzilla contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the 'votes.cgi' script does not require multiple steps or explicit confirmation for certain sensitive transactions, allowing for the hijacking of arbitrary user's authentication. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-01-24
|
Bugzilla votes.cgi Authentication Hijack CSRF
|
|
70707
Description:
Bugzilla contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the 'sanitycheck.cgi' script does not require multiple steps or explicit confirmation for certain sensitive transactions, allowing for the hijacking of arbitrary user's authentication. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-01-24
|
Bugzilla sanitycheck.cgi Authentication Hijack CSRF
|
|
70708
Description:
Bugzilla contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the 'chart.cgi' script does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of charts. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-01-24
|
Bugzilla chart.cgi Chart Manipulation CSRF
|
|
70709
Description:
Bugzilla contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the 'colchange.cgi' script does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of columns. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-01-24
|
Bugzilla colchange.cgi Column Manipulation CSRF
|
|
70710
Description:
Bugzilla contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the 'quips.cgi' script does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of quips. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-01-24
|
Bugzilla quips.cgi Quip Moderation CSRF
|
|
70596
Description:
Pango is prone to an overflow condition. The 'pango_ft2_font_render_box_glyph()' function in 'pango/pangoft2-render.c' fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted font, a context-dependent attacker can cause a denial of service.
|
2011-01-21
|
Pango pango/pangoft2-render.c pango_ft2_font_render_box_glyph() Function Overflow DoS
|
|
73403
Description:
(Description Provided by CVE) : Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.
|
2011-01-21
|
Wireshark wiretap/pcapng.c Crafted Capture File Overflow DoS
|
|
70519
Description:
IBM AIX contains a flaw that may allow a local denial of service. The issue is triggered when an error in the FC SCSI protocol driver when deallocating a timer occurs, allowing a local attacker to cause a denial of service.
|
2011-01-20
|
IBM AIX FC SCSI Protocol Driver Timer Deallocation Local DoS
|
|
70520
Description:
FUSE contains a flaw that may allow a local denial of service. The issue is triggered when an error within the 'fusermount' utility when performing unmount operations occurs, allowing a local attacker to cause a denial of service by unmounting arbitrary mounts via symlink attacks.
|
2011-01-19
|
Fuse fusermount Arbitrary Unmount Local DoS
|
|
70661
Description:
Best Practical Solutions RT contains a flaw related to the MD5 algorithm for password hashes. This may allow disclose cleartext passwords to a context-dependent attacker via a brute-force attack.
|
2011-01-19
|
RT MD5 Password Hash Storage Brute-force Weakness
|
|
70543
Description:
Oracle Fusion Middleware Outside In Technology contains a flaw that may allow a local denial of service. The issue is triggered when an unspecified error in the 'Outside In Viewer SDK' component occurs, allowing a remote attacker to cause a denial of service.
|
2011-01-18
|
Oracle Fusion Middleware Outside In Technology Outside In Viewer SDK Unspecified Remote DoS
|
|
70539
Description:
Oracle Industry Applications Health Sciences - Oracle Argus Safety contains a flaw related to LDAP login handling that may allow a remote attacker to partially affect confidentiality, integrity, and availability. No further details have been provided.
|
2011-01-18
|
Oracle Industry Applications Health Sciences - Oracle Argus Safety Login / LDAP Unspecified Remote Issue
|
|
70569
Description:
CDE contains a flaw related to the 'CDE Calendar Manager Service Daemon' sub-component that may allow a remote attacker to execute arbitrary code via specially crafted RPC packets. No further details have been provided.
|
2011-01-18
|
CDE Calendar Manager Service Daemon / RPC Remote Code Execution
|
|
70537
Description:
Oracle Fusion Middleware Document Capture contains a flaw related to the ActiveBar2Library ActiveX (Actbar2.ocx). The ActiveX control allows an attacker to overwrite any 'unhidden' file using the 'SaveLayoutChanges' method.
|
2011-01-18
|
Oracle Fusion Middleware Document Capture ActiveBar2Library ActiveX (Actbar2.ocx) SaveLayoutChanges Method Arbitrary File Overwrite
|
|
70551
Description:
Oracle Fusion Middleware is prone to an overflow condition. The 'Server' subcomponent in the 'GoldenGate Veridata' component fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted an overly long XML soap request, a remote attacker can potentially execute arbitrary code.
|
2011-01-18
|
Oracle Fusion Middleware GoldenGate Veridata Server XML SOAP Request Remote Overflow
|
|
70565
Description:
Oracle Sun Java System Portal Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an unspecified error in the 'Proxy' component occurs, which will disclose unspecified information to a local attacker.
|
2011-01-18
|
Oracle Sun Products Suite Sun Java System Portal Server Component Proxy Unspecified Local Information Disclosure
|
|
70571
Description:
Oracle Fusion Middleware contains a flaw related to the 'Servlet Container' sub-component in the 'Oracle WebLogic Server' component that may allow a remote attacker to gain update, insert, or delete access to certain data. No further details have been provided.
|
2011-01-18
|
Oracle Fusion Middleware WebLogic Server Servlet Container AFSSESSIONID Cookie Session Fixation
|
|
70573
Description:
Sun Java System Message Queue contains a flaw related to the 'Java Message Service (JMS)' sub-component that may allow a local attacker to have a partial affect on integrity and confidentiality and cause a denial of service. No further details have been provided.
|
2011-01-18
|
Oracle Sun Products Suite Sun Java System Message Queue / Sun GlassFish Enterpriser Serve Components Unspecified Local Issue
|
|
70579
Description:
Sun Java System Access Manager contains an unspecified flaw that may allow a remote attacker to perform unauthorised insertion, deletion, or updating of certain. No further details have been provided.
|
2011-01-18
|
Oracle Sun Products Suite Sun Java System Access Manager / Oracle OpenSSO Components Unspecified Remote Issue
|
|
70583
Description:
Oracle Audit Vault contains a flaw related to the 'av' component's failure to properly validate code when handling 'action.execute' requests, allowing the creation of arbitrary objects. This may allow a remote attacker to execute arbitrary code.
|
2011-01-18
|
Oracle Audit Vault av Component action.execute Crafted Parameter Remote Code Execution
|
|
70639
Description:
OpenVAS Manager is vulnerable to command injection due to insufficient validation of user supplied data when processing OMP requests. It has been identified that this vulnerability allows privilege escalation within the OpenVAS Manager but more complex injection may allow arbitrary code to be executed with the privileges of the OpenVAS Manager on vulnerable systems.
|
2011-01-18
|
OpenVAS Manager manage_sql.c Email Function OMP Request Command Injection
|
|
70530
Description:
Oracle Supply Chain Products Suite Agile Core Folders, Files & Attachments contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an unspecified error occurs, which will disclose unspecified information to a remote authenticated attacker.
|
2011-01-18
|
Oracle Supply Chain Products Suite Agile Core Folders, Files & Attachments Unspecified Remote Information Disclosure
|
|
70531
Description:
The Oracle WebLogic Server component in Oracle Fusion Middleware contains an unspecified flaw related to the 'Node Manager' subcomponent that may allow an attacker to severely affect confidentiality, integrity, and availability. No further details have been provided.
|
2011-01-18
|
Oracle Fusion Middleware WebLogic Server Node Manager Unspecified Issue
|
|
70533
Description:
Oracle Applications Common Applications contains a flaw related to the 'User Management' component that may allow a remote attacker to perform an unauthorized update. No further details have been provided.
|
2011-01-18
|
Oracle Applications Common Applications User Management Unspecified Remote Issue
|
|
70534
Description:
Oracle Fusion Middleware Discoverer contains a flaw related to the 'EUL Code & Schema' component that may allow a remote authenticated attacker to gain read, update, insert, or delete access to certain data. No further details have been provided.
|
2011-01-18
|
Oracle Fusion Middleware Discoverer EUL Code & Schema Unspecified Remote Issue
|
|
70535
Description:
Oracle Applications Application Object Library contains a flaw related to the 'Logout' subcomponent that may allow an attacker to to gain read, insert and delete access and perform an unauthorized update. No further details have been provided.
|
2011-01-18
|
Oracle Applications Application Object Library Logout Unspecified Remote Issue
|
|
70536
Description:
Oracle Database Server Spatial contains a flaw related to the 'MDSYS' component that may allow an attacker to gain read, insert, and delete access and perform an unauthorized update. No further details have been provided.
|
2011-01-18
|
Oracle Database Server Spatial MDSYS Unspecified Remote Issue
|
|
70538
Description:
Oracle Fusion Middleware Document Capture contains a flaw related to the 'Internal Operations' component that may allow an attacker to gain write access to arbitrary files and cause a denial of service. No further details have been provided.
|
2011-01-18
|
Oracle Fusion Middleware Document Capture Internal Operations Unspecified Remote Issue (2010-3592)
|
|
70541
Description:
Oracle Fusion Middleware Document Capture contains a flaw that may lead to arbitrary file disclosure. The issue is due to the EasyMail ActiveX (emsmtp.dll) not properly restricting access to the ImportBodyText method. By requesting a file (e.g., c:\\boot.ini), the ActiveX will display the contents of the file.
|
2011-01-18
|
Oracle Fusion Middleware Document Capture Import Server EasyMail ActiveX (emsmtp.dll) ImportBodyText Method Arbitrary File Access
|
|
70542
Description:
Oracle Secure Backup contains a flaw related to the 'mod_ssl' component that may allow a remote attacker to insert, delete, or update certain data . No further details have been provided.
|
2011-01-18
|
Oracle Secure Backup mod_ssl Unspecified Remote Issue
|
|
70544
Description:
Oracle Fusion Middleware Document Capture contains a flaw related to the 'Import Export Utility' component that may allow a remote attacker to gain write access to arbitrary files. No further details have been provided.
|
2011-01-18
|
Oracle Fusion Middleware Document Capture Import Export Utility Unspecified Remote Issue
|
|
70545
Description:
Oracle Fusion Middleware Document Capture Import Server contains a flaw that may allow an attacker to overwrite arbitrary files. The issue is due to the NCSECWLib ActiveX not properly sanitizing input to the WriteJPG function. Additionally, this function has been reported to be vulnerable to an overflow, although the initial disclosure does not indicate if it is exploitable.
|
2011-01-18
|
Oracle Fusion Middleware Document Capture Import Server NCSECWLib ActiveX WriteJPG Function Arbitrary File Overwrite
|
|
70546
Description:
Oracle Database Server Client System Analyzer contains a flaw related to a JSP script exposed via an HTTPS server running by default on TCP port 1158. The issue is triggered when a remote attacker supplies a NULL byte within a POST parameter during a request to this JSP script. This may allow an attacker to upload arbitrary code, which can later be executed remotely.
|
2011-01-18
|
Oracle Database Server Client System Analyzer Remote Code Execution
|
|
70547
Description:
Oracle Enterprise Manager Grid Control Client System Analyzer contains a flaw related to a JSP script exposed via an HTTPS server running by default on TCP port 1158. The issue is triggered when a remote attacker supplies a NULL byte within a POST parameter during a request to this JSP script. This may allow an attacker to upload arbitrary code, which can later be executed remotely.
|
2011-01-18
|
Oracle Enterprise Manager Grid Control Client System Analyzer Remote Code Execution
|
|
70548
Description:
Oracle Database Server Scheduler Agent contains an unspecified flaw that may allow a remote attacker to gain read, insert, and delete access and perform an unauthorized update. No further details have been provided.
|
2011-01-18
|
Oracle Database Server Scheduler Agent Unspecified Remote Issue
|
|
70549
Description:
Oracle VM VirtualBox contains a flaw related to the 'Extensions' component that may allow a local attacker to severely affect confidentiality, integrity, and availability. No further details have been provided.
|
2011-01-18
|
Oracle VM VirtualBox Extensions Unspecified Local Issue
|
|
70552
Description:
Oracle Fusion Middleware contains a flaw related to the 'Services for Beehive' component. The issue is triggered when a remote attacker passes input via an evaluation parameter to voice-servlet/prompt-qa/Index.jspf. The program does not properly sanitise this input before using it to create a file. This may allow a remote attacker to execute arbitrary JSP code by creating a file with a NULL byte within the filename.
|
2011-01-18
|
Oracle Fusion Middleware Services for Beehive voice-servlet/prompt-qa/Index.jspf Filename Null Byte Remote Code Execution
|
|
70555
Description:
Oracle Database Server contains a flaw related to the Database Vault component that may lead to an unauthorized information disclosure. The issue is triggered when the Monitor web page is accessed by an administrator and generates universally readable .gif files in ORACLE_HOME/dv/jlib/dva_webapp/dva_webapp/images/dvcache which contain valid session IDs in their names, which will disclose session IDs to a local attacker, allowing them to impersonate arbitrary users.
|
2011-01-18
|
Oracle Database Server Database Vault GIF Filename Local Session ID Disclosure Weakness
|