| OSVDB ID | Disclosure Date | Title |
|
71494
Description:
IBM solidDB contains a flaw related to the solid.exe process failing to verify password hash lengths properly. This may allow a remote attacker to specify the password hash length, allowing them to bypass authentication via a crafted request which contains the first few bytes of the password hash.
|
2011-04-01
|
IBM solidDB Password Hash Verification Bypass Remote Code Execution
|
|
71883
Description:
(Description Provided by CVE) : tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option.
|
2011-03-31
|
tmux Group Privilege Dropping Weakness Local Privilege Escalation
|
|
72300
Description:
WebSphere contains a flaw related to the Application Server on z/OS. The issue is triggered when incorrect permissions are set, which may grant users unintended access to WebSphere applications.
|
2011-03-31
|
IBM WebSphere Application Server for z/OS Permissions Weakness Access Restriction Bypass
|
|
71468
Description:
IBM WEBi contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-31
|
IBM WEBi Unspecified XSS
|
|
71585
Description:
HP Network Node Manager i (NNMi) contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an unspecified condition occurs, which will disclose unspecified information to a remote attacker.
|
2011-03-30
|
HP Network Node Manager i (NNMi) Unspecified Remote Information Disclosure
|
|
72289
Description:
Cisco ACS contains a flaw related to the web interface. The issue is triggered when a remote attacker uses a malformed URL to change any user password to an arbitrary value. This may allow an attacker to reset any user password.
|
2011-03-30
|
Cisco Secure Access Control System Arbitrary User Password Modification
|
|
72186
Description:
Cyrus IMAP Server contains a flaw related to the TLS implementation failing to properly clear transport layer buffers when changing from plaintext to ciphertext upon receipt of the 'STARTTLS' command. This may allow a remote attacker to inject arbitrary plaintext data which will be executed upon transition to ciphertext.
|
2011-03-30
|
Cyrus IMAP Server STARTTLS Arbitrary Plaintext Command Injection
|
|
71426
Description:
HP Operations for UNIX contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-29
|
HP Operations for UNIX Unspecified XSS
|
|
71427
Description:
HP Operations for UNIX contains an unspecified flaw that may allow an attacker to bypass access restrictions. No further details have been provided.
|
2011-03-29
|
HP Operations for UNIX Unspecified Access Restriction Bypass
|
|
71783
Description:
(Description Provided by CVE) : VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might allow local users to gain privileges via a Trojan horse shared library in an unspecified directory.
|
2011-03-29
|
VMware Workstation vmrun Unspecified Shared Library Local Privilege Escalation
|
|
72551
Description:
(Description Provided by CVE) : GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
|
2011-03-28
|
GNOME Display Manager (gdm) /var/cache/gdm/ Multiple File Symlink Local Privilege Escalation
|
|
71353
Description:
HP Diagnostics contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-28
|
HP Diagnostics Unspecified XSS
|
|
71287
Description:
Andys PHP Knowledgebase Project contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the plugins/pdfClasses/pdfgen.php not properly sanitizing user-supplied input to the 'pdfa' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-27
|
Andy's PHP Knowledgebase Project plugins/pdfClasses/pdfgen.php pdfa Parameter SQL Injection
|
|
71281
Description:
Picasa is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2011-03-25
|
Google Picasa Path Subversion Arbitrary DLL Injection Code Execution
|
|
72267
Description:
Google Chrome contains an array-indexing error condition in the 'ToUpper' and 'ToLower' functions [ui/base/l10n/l10n_util.cc]. The issue is triggered as user-supplied input containing embedded NULLs is not properly handled when selecting and right-clicking text. With a specially crafted web page, a context-dependent attacker can cause data to be written outside the bounds of an array, resulting in the browser crashing and potentially allowing code execution.
|
2011-03-25
|
Google Chrome Base String Handling Embedded NULL Array Indexing Error
|
|
72262
Description:
WebKit contains a stale pointer flaw in the SVG component. The issue is triggered as SVGHKernElement::insertedIntoDocument [Source/WebCore/svg/SVGHKernElement.cpp] and SVGVKernElement::insertedIntoDocument [Source/WebCore/svg/SVGVKernElement.cpp] do not call SVGElement::insertedIntoDocument, resulting in descendants of these elements not being informed of insertion and removal from the DOM. With a specially crafted web page, a context-dependent attacker can dereference incorrect memory and potentially execute arbitrary code.
|
2011-03-25
|
WebKit SVG Text Handling 'insertedIntoDocument' Stale Pointer
|
|
71685
Description:
(Description Provided by CVE) : EMC Data Protection Advisor Collector 5.7 and 5.7.1 on Solaris SPARC platforms uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
|
2011-03-25
|
EMC Data Protection Advisor Collector on SPARC Unspecified Local Privilege Escalation
|
|
72266
Description:
Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when by an unspecified issue in the Frame Loader, and will result in loss of availability for the application.
|
2011-03-25
|
Google Chrome Frame Loader Use-after-free DoS
|
|
72265
Description:
Chrome contains a flaw that may allow a remote denial of service. The issue is triggered by an unspecified HTMLCollection issue, and will result in loss of availability for the application.
|
2011-03-25
|
Google Chrome HTMLCollection Use-after-free DoS
|
|
72264
Description:
Chrome contains a flaw that may allow a remote denial of service. The issue is triggered by malformed CSS token sequences, and will result in loss of availability for the application.
|
2011-03-25
|
Google Chrome CSS Handling Stale Pointer DoS
|
|
72263
Description:
Chrome contains a flaw that may allow a remote denial of service. The issue is triggered by broken node parentage, and will result in loss of availability for the application.
|
2011-03-25
|
Google Chrome Broken Node Parentage DOM Tree Corruption
|
|
71277
Description:
VLC Media Player is prone to an overflow condition. libdirectx_plugin.dll fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted width in an AMV file, a context-dependent attacker can potentially execute arbitrary code.
|
2011-03-23
|
VLC Media Player libdirectx_plugin.dll AMV File Large Video Dimension Overflow
|
|
71278
Description:
VLC Media Player is prone to an overflow condition. libdirectx_plugin.dll fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted width in an NSV file, a context-dependent attacker can potentially execute arbitrary code.
|
2011-03-23
|
VLC Media Player libdirectx_plugin.dll NSV File Large Video Dimension Overflow
|
|
71876
Description:
KDE Konqueror contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the URL when it is displayed via the error page upon submission to the 'HTMLPart::htmlError()' function in 'khtml/khtml_part.cpp'. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-23
|
KDE Konqueror khtml/khtml_part.cpp KHTMLPart::htmlError() Function Error Page XSS
|
|
72302
Description:
A memory corruption flaw exists in t1lib. The font handling function fails to sanitize user-supplied input using Type 1 fonts resulting in memory corruption. With a specially crafted PDF file, a context-dependent attacker can execute arbitrary code.
|
2011-03-23
|
t1lib PDF Type 1 Font Handling Invalid Pointer Code Execution
|
|
73600
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
|
2011-03-23
|
Apache Struts javatemplates Plugin Component Handlers .action URI Multiple Parameter XSS
|
|
76075
Description:
(Description Provided by CVE) : The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.
|
2011-03-23
|
IBM AIX QLogic Adapter DMA Resource Weakness Local DoS
|
|
71279
Description:
Loggerhead contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input related to the filename is in loggerhead/templatefunctions.py script before being displayed in revision view filenames. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-22
|
Loggerhead loggerhead/templatefunctions.py Revision View Filename XSS
|
|
74630
Description:
(Description Provided by CVE) : The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
|
2011-03-22
|
tex-common conf/texmf.d/95NonPath.cnf shell_escape_commands Directive Crafted TeX Document Remote Code Execution
|
|
71259
Description:
Quagga contains a flaw that may allow a remote denial of service. The issue is triggered when a NULL-pointer dereference error occurs, allowing a remote attacker to use crafted extended community attributes to crash the 'bgpd' daemon, resulting in a loss of availability.
|
2011-03-22
|
Quagga Extended Communities Attribute Handling NULL Dereference Remote DoS
|
|
71258
Description:
Quagga contains a flaw that may allow a remote denial of service. The issue is triggered when the AS path limit/TTL functionality encounters an error when parsing some specific AS_PATHLIMIT attributes, allowing a remote attacker to use crafted AS_PATHLIMIT attributes to reset BGP sessions, resulting in a loss of availability.
|
2011-03-22
|
Quagga AS_PATHLIMIT BGP Session Reset Remote DoS
|
|
71261
Description:
Symantec LiveUpdate Administrator contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the execution of arbitrary commands, creation of administrative users, or insertion of scripts. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-03-22
|
Symantec LiveUpdate Administrator Multiple Admin Function CSRF
|
|
72827
Description:
(Description Provided by CVE) : Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) On_FC_MISC_FCS_MSGBROADCAST and (2) On_FC_MISC_FCS_MSGSEND packets, which trigger a heap-based buffer overflow.
|
2011-03-21
|
RealFlex RealWin On_FC_MISC_FCS_* Packets Multiple Remote Overflows
|
|
72834
Description:
(Description Provided by CVE) : Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via unspecified vectors related to a crafted POST request. NOTE: some sources have reported this issue as SQL injection, but this might not be accurate.
|
2011-03-21
|
Ecava IntegraXor HMI Unspecified SQL Injection
|
|
72354
Description:
IGSS contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to IGSSdataServer.exe not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 0xd opcode. This directory traversal attack would allow the attacker to manipulate arbitrary files.
|
2011-03-21
|
7-Technologies Interactive Graphical SCADA System (IGSS) IGSSdataServer.exe Packet Handling Opcode 0xd Traversal Arbitrary File Manipulation
|
|
73222
Description:
(Description Provided by CVE) : HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive information or have unspecified other impact by leveraging the public read community.
|
2011-03-21
|
HP Discovery & Dependency Mapping Inventory (DDMI) Windows SNMP Read Community String Remote Information Disclosure
|
|
72353
Description:
IGSS is prone to an overflow condition. IGSSdataServer.exe fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted request, a remote attacker can potentially cause arbitrary code execution.
|
2011-03-21
|
7-Technologies Interactive Graphical SCADA System (IGSS) IGSSdataServer.exe Multiple Command Overflow
|
|
72352
Description:
IGSS is prone to an overflow condition. IGSSdataServer.exe fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted request, a remote attacker can potentially cause arbitrary code execution.
|
2011-03-21
|
7-Technologies Interactive Graphical SCADA System (IGSS) IGSSdataServer.exe RMS Reports Multiple Command Overflow
|
|
72351
Description:
A format string flaw exists in IGSS. IGSSdataServer.exe fails to properly sanitize format string specifiers (e.g., %s and %x). With a specially crafted request, a remote attacker can crash the service or possibly execute arbitrary code.
|
2011-03-21
|
7-Technologies Interactive Graphical SCADA System (IGSS) IGSSdataServer.exe logText() Function Format String
|
|
72350
Description:
IGSS is prone to an overflow condition. IGSSdataServer fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted STDREP request, a remote attacker can potentially cause arbitrary code execution.
|
2011-03-21
|
7-Technologies Interactive Graphical SCADA System (IGSS) IGSSdataServer.exe STDREP Request SQL Query String Overflow
|