| OSVDB ID | Disclosure Date | Title |
|
72615
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.
|
2011-04-27
|
Cisco Unified Communications Manager xmldirectorylist.jsp Multiple Parameter SQL Injection
|
|
72700
Description:
(Description Provided by CVE) : IBM solidDB 4.5.x before 4.5.182, 6.0.x before 6.0.1069, 6.1.x and 6.3.x before 6.3 FP8 (aka 6.3.49), and 6.5.x before 6.5 FP4 (aka 6.5.0.4) does not properly handle the (1) rpc_test_svc_readwrite and (2) rpc_test_svc_done commands, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted command.
|
2011-04-26
|
IBM solidDB rpc_test_svc Commands Handling NULL Dereference Remote DoS
|
|
72124
Description:
CA Arcot WebFort Versatile Authentication Server contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-26
|
CA Arcot WebFort Versatile Authentication Server Unspecified XSS
|
|
72125
Description:
CA Arcot WebFort Versatile Authentication contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate certain unspecified input. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing. Such attacks are useful as the crafted URL initially appear to be a web page of a trusted site. This could be leveraged to direct an unsuspecting user to a web page containing attacks that target client side software such as a web browser or document rendering programs.
|
2011-04-26
|
CA Arcot WebFort Versatile Authentication Server Unspecified Arbitrary Site Redirect
|
|
72697
Description:
(Description Provided by CVE) : IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.
|
2011-04-22
|
IBM DB2 Relational Data Services Non-DDL Statement Execution
|
|
72698
Description:
(Description Provided by CVE) : IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce privilege requirements for table access, which allows remote authenticated users to modify SYSSTAT.TABLES statistics columns via an UPDATE statement. NOTE: some of these details are obtained from third party information.
|
2011-04-22
|
IBM DB2 Relational Data Services SYSSTAT.TABLES Statistics Manipulation
|
|
73433
Description:
(Description Provided by CVE) : Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space exhaustion) via a series of TCP connections.
|
2011-04-22
|
Asterisk Multiple Products Unauthenticated Session Connection Saturation Remote DoS
|
|
73434
Description:
(Description Provided by CVE) : manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 does not properly check for the system privilege, which allows remote authenticated users to execute arbitrary commands via an Originate action that has an Async header in conjunction with an Application header.
|
2011-04-22
|
Asterisk Multiple Products Manager Interface manager.c Originate Action Remote Command Execution
|
|
72061
Description:
HP SiteScope contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-21
|
HP SiteScope Unspecified XSS (2011-1727)
|
|
72130
Description:
(Description Provided by CVE) : The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances via an NFS mount request.
|
2011-04-20
|
FreeBSD mountd mountd.c makemask Function NFS Mount Request Access Restriction Bypass
|
|
71946
Description:
Oracle Sun Java System Messaging Server contains a flaw related to the TLS implementation within the SMTP, IMAP and POP servers failing to properly clear transport layer buffers when changing from plaintext to ciphertext upon receipt of the 'STARTTLS' command. This may allow a remote attacker to inject arbitrary plaintext data which will be executed upon transition to ciphertext.
|
2011-04-20
|
Oracle Sun Java System Messaging Server SMTP Server / IMAP Server / POP Server STARTTLS Arbitrary Plaintext Command Injection
|
|
74357
Description:
CA SiteMinder contains a flaw in the Web Agents component that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when parsing multi-line headers, allowing a remote authenticated attacker to gain the privileges of the current user.
|
2011-04-20
|
CA SiteMinder Web Agents Multi-line Header Injection Spoofing Remote Privilege Escalation
|
|
74343
Description:
CA Output Management Web Viewer is prone to an overflow condition. The UOMWV_Helper ActiveX control fails to properly sanitize user supplied input, resulting in a stack-based buffer overflow. With a specially crafted overly long string passed via the 'title' property, a remote attacker can potentially execute arbitrary code.
|
2011-04-20
|
CA Output Management Web Viewer UOMWV_Helper ActiveX (UOMWV_HelperActiveX.ocx) Title Property Overflow
|
|
74344
Description:
CA Output Management Web Viewer is prone to an overflow condition. The ActiveX control fails to properly sanitize user supplied input, resulting in a stack-based buffer overflow. With a specially crafted overly long string passed via the 'SRC' object parameter, a remote attacker can potentially execute arbitrary code.
|
2011-04-20
|
CA Output Management Web Viewer PPSViewer ActiveX (PPSView.ocx) SRC Parameter Overflow
|
|
74943
Description:
KGet in KDE contains a flaw that allows an attacker to traverse outside of a restricted path. The issue is due to the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the name attribute of a file element in a metalink file. This directory traversal attack would allow a remote attacker to create arbitrary files.
|
2011-04-19
|
KDE KGet ui/metalinkcreator/metalinker.cpp KGetMetalink::File::isValidNameAttr Function Traversal Arbitrary File Creation
|
|
71967
Description:
(Description Provided by CVE) : Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x allows remote authenticated users to obtain access to processes via unknown vectors.
|
2011-04-18
|
HP Network Node Manager i (NNMi) Unspecified Remote Access Restriction Bypass
|
|
71871
Description:
EMC NetWorker contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered due to an unspecified file having weak permissions, allowing a local attacker to execute arbitrary code.
|
2011-04-18
|
EMC NetWorker Unspecified File Permissions Weakness Local Privilege Escalation
|
|
74177
Description:
(Description Provided by CVE) : dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2) SetSystemDefaultLanguageEnv functions, which allows local users to gain privileges via shell metacharacters in a string argument, a different vulnerability than CVE-2011-0729.
|
2011-04-18
|
language-selector dbus_backend/lsd.py Multiple Function Shell Metacharacter Local Privilege Escalation
|
|
74178
Description:
(Description Provided by CVE) : dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result, which allows local users to modify the /etc/default/locale and /etc/environment files via a (1) SetSystemDefaultLangEnv or (2) SetSystemDefaultLanguageEnv call.
|
2011-04-18
|
language-selector dbus_backend/ls-dbus-backend PolicyKit Check Result Local Access Restriction Bypass
|
|
71848
Description:
Wireshark is prone to an overflow condition. The DECT dissector in epan/dissectors/packet-dect.c fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted packet, a remote attacker can potentially execute arbitrary code.
|
2011-04-15
|
Wireshark epan/dissectors/packet-dect.c DECT Dissector Overflow
|
|
71847
Description:
Wireshark on Windows contains a flaw that may allow a remote denial of service. The issue is triggered when a data type mismatch error occurs within the NFS dissector in epan/dissectors/packet-nfs.c, allowing an attacker to cause a denial of service via specially crafted packets.
|
2011-04-15
|
Wireshark on Windows epan/dissectors/packet-nfs.c NFS Dissector DoS
|
|
73801
Description:
ANGLE WebGLES graphics library contains an overflow condition in the 'AddString' function [compiler/preprocessor/atom.c] that is triggered when loading a shader from file. With a specially crafted web page, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially executing arbitrary code.
|
2011-04-14
|
ANGLE WebGLES Graphics Library AddString Shader Loading Overflow
|
|
71846
Description:
Wireshark contains a flaw that may allow a remote denial of service. The issue is triggered when a use-after-free error occurs within the X.509if dissector, allowing an attacker to cause a denial of service via specially crafted packets.
|
2011-04-14
|
Wireshark X.509if Dissector Use-after-free DoS
|
|
73800
Description:
(Description Provided by CVE) : Use-after-free vulnerability in the GPU process in Google Chrome before 10.0.648.205 allows remote attackers to execute arbitrary code via unknown vectors.
|
2011-04-14
|
Google Chrome GPU Process Use-after-free Remote Code Execution
|
|
71857
Description:
RSA Adaptive Authentication contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input related to a Flash Shockwave file before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-14
|
RSA Adaptive Authentication Flash Shockwave File Unspecified XSS
|
|
74793
Description:
(Description Provided by CVE) : Best Practical Solutions RT 3.8.0 through 3.8.9 and 4.0.0rc through 4.0.0rc7, when the CustomFieldValuesSources (aka external custom field) option is enabled, allows remote authenticated users to execute arbitrary code via unspecified vectors, as demonstrated by a cross-site request forgery (CSRF) attack.
|
2011-04-14
|
RT External Custom Field Unspecified Remote Code Execution
|
|
74794
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, as demonstrated by reading data.
|
2011-04-14
|
RT Multiple Unspecified SQL Injection
|
|
74795
Description:
(Description Provided by CVE) : Best Practical Solutions RT 3.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote authenticated users to obtain sensitive information by using the search interface, as demonstrated by retrieving encrypted passwords.
|
2011-04-14
|
RT Search Interface Encrypted Password Disclosure
|
|
74796
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Best Practical Solutions RT 3.2.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote attackers to read arbitrary files via a crafted HTTP request.
|
2011-04-14
|
RT Unspecified Traversal Arbitrary File Access
|
|
74797
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2011-04-14
|
RT Multiple Unspecified XSS
|
|
74798
Description:
(Description Provided by CVE) : Best Practical Solutions RT 3.6.0 through 3.6.10 and 3.8.0 through 3.8.8 allows remote attackers to trick users into sending credentials to an arbitrary server via unspecified vectors.
|
2011-04-14
|
RT Unspecified Authentication Credentials Disclosure
|
|
74968
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2) UnassignAdminRoles, (3) DeleteFilter, (4) NonAssignedUserList, (5) DeleteReportLayout, (6) DeleteReports, and (7) RegenerateReport stored procedures.
|
2011-04-13
|
CA Total Defense management.asmx Multiple Stored Procedure SQL Injection
|
|
71790
Description:
OTRS (Open Ticket Request System) contains multiple flaws that allow remote cross-site scripting (XSS) attacks. These flaws exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-13
|
OTRS (Open Ticket Request System) Multiple Unspecified XSS
|
|
71740
Description:
Microsoft Windows contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when a local, context-dependent attacker uses a crafted application which leverages incorrect driver object management, allowing them to gain elevated privileges.
|
2011-04-13
|
Microsoft Windows win32k.sys Driver Use After Free Unspecified Local Privilege Escalation (2011-0662)
|
|
71727
Description:
Microsoft Windows contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when a local, context-dependent attacker uses a crafted application to trigger a null pointer dereference, allowing them to gain elevated privileges.
|
2011-04-13
|
Microsoft Windows win32k.sys Driver NULL Pointer De-reference Unspecified Local Privilege Escalation (2011-0673)
|
|
71728
Description:
Microsoft Windows contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when a local, context-dependent attacker uses a crafted application to trigger a null pointer dereference, allowing them to gain elevated privileges.
|
2011-04-13
|
Microsoft Windows win32k.sys Driver NULL Pointer De-reference Unspecified Local Privilege Escalation (2011-0676)
|
|
71729
Description:
Microsoft Windows contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when a local, context-dependent attacker uses a crafted application to trigger a null pointer dereference, allowing them to gain elevated privileges.
|
2011-04-13
|
Microsoft Windows win32k.sys Driver NULL Pointer De-reference Unspecified Local Privilege Escalation (2011-0677)
|
|
71730
Description:
Microsoft Windows contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when a local, context-dependent attacker uses a crafted application to trigger a null pointer dereference, allowing them to gain elevated privileges.
|
2011-04-13
|
Microsoft Windows win32k.sys Driver NULL Pointer De-reference Unspecified Local Privilege Escalation (2011-1225)
|
|
71731
Description:
Microsoft Windows contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when a local, context-dependent attacker uses a crafted application to trigger a null pointer dereference, allowing them to gain elevated privileges.
|
2011-04-13
|
Microsoft Windows win32k.sys Driver NULL Pointer De-reference Unspecified Local Privilege Escalation (2011-1226)
|
|
71732
Description:
Microsoft Windows contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when a local, context-dependent attacker uses a crafted application to trigger a null pointer dereference, allowing them to gain elevated privileges.
|
2011-04-13
|
Microsoft Windows win32k.sys Driver NULL Pointer De-reference Unspecified Local Privilege Escalation (2011-1227)
|