| OSVDB ID | Disclosure Date | Title |
|
71408
Description:
Novell Netware is prone to an overflow condition. The 'xdrDecodeString()' function in XNFS.NLM fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted signed value in a NFS RPC request to UDP port 1234, a remote attacker can potentially execute arbitrary code.
|
2011-02-19
|
Novell Netware XNFS.NLM xdrDecodeString() Function RPC Request Parsing Remote Overflow
|
|
70958
Description:
Ruby contains a race condition flaw that may allow a malicious local user to delete arbitrary files on the system. The issue is due to the 'FileUtils.remove_entry_secure' method creating temporary files insecurely. It is possible for a local attacker to use a symlink attack to cause the program to unexpectedly write to, or overwrite an attacker specified file.
|
2011-02-19
|
Ruby FileUtils.remove_entry_secure Method File Symlink Race Condition Arbitrary File Deletion
|
|
70895
Description:
shadow contains multiple CRLF injection vulnerabilities related to the 'chfn' and 'chsh' utilities failing to handle newlines characters properly. This may allow a local attacker to add new groups or users to the 'etc/passwd' file via the GECOS field.
|
2011-02-18
|
shadow chfn/chsh Utility GECOS Field CRLF Injection
|
|
70947
Description:
PyWebDAV contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'get_userinfo()' method in 'DAVServer/mysqlauth.py' not properly sanitizing user-supplied input to the 'user' and 'pw' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-02-18
|
PyWebDAV DAVServer/mysqlauth.py get_userinfo() Multiple Parameter SQL Injection
|
|
70957
Description:
Ruby contains a flaw related to the safe-level feature. The issue is triggered when a context-dependent attacker exploits a flaw within the exception '#to_s' handling. This may allow an attacker to bypass safe-level protection and modify strings via the 'Exception#to_s' method.
|
2011-02-18
|
Ruby Exception#to_s Method Safe Level Security Bypass
|
|
72536
Description:
(Description Provided by CVE) : jingle-factory.c in Telepathy Gabble 0.11 before 0.11.7, 0.10 before 0.10.5, and 0.8 before 0.8.15 allows remote attackers to sniff audio and video calls via a crafted google:jingleinfo stanza that specifies an alternate server for streamed media.
|
2011-02-17
|
Telepathy Gabble jingle-factory.c Crafted google:jingleinfo Stanza Remote Call Interception
|
|
71403
Description:
Novell ZENworks Configuration Management is prone to an overflow condition. The novell-tftp.exe component fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted long TFTP request sent to UDP port 69, a remote attacker can potentially cause execute arbitrary code.
|
2011-02-17
|
Novell ZENworks Configuration Management novell-tftp.exe TFTP Request Overflow
|
|
71011
Description:
Best Practical Solutions Request Tracker contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when 'Scrips_Overlay.pm' fails to properly restrict access to 'TicketObj' in a 'Scrip' following a 'CurrentUser' change, which will disclose potentially sensitive information to a remote authenticated attacker.
|
2011-02-16
|
RT Scrips_Overlay.pm TicketObj Access Unspecified Information Disclosure
|
|
71012
Description:
Best Practical Solutions Request Tracker contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the program fails to perform certain redirect actions upon login, which will disclose login credentials to a physically present attacker who uses a web browser's back button after a logout.
|
2011-02-16
|
RT Form Data Resubmission Login Credentials Disclosure
|
|
71358
Description:
Logwatch contains a flaw related to logwatch.pl failing to properly sanitize log file filenames before use in 'system()' calls. This may allow a remote attacker to inject and execute shell commands.
|
2011-02-16
|
Logwatch Log Filename Arbitrary Command Injection
|
|
71682
Description:
(Description Provided by CVE) : IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.
|
2011-02-16
|
IBM FileNet Multiple Products P8 Content Engine Privileged Object Property Remote Modification
|
|
70884
Description:
Cisco Security Agent contains a flaw related to the Management Center web interface, webagent.exe failing to properly process certain POST parameters when handling an 'st_upload' request. This may allow a remote attacker to create arbitrary files with a crafted 'st_upload' request, allowing for the execution of arbitrary code through those files.
|
2011-02-16
|
Cisco Security Agent Management Center webagent.exe st_upload Request Arbitrary File Upload
|
|
71075
Description:
Apache Archiva contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain requests containing specially crafted request parameters upon submission to the user management page. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-02-16
|
Apache Archiva User Management Page XSS
|
|
70952
Description:
IBM FileNet Content Manager contains an unspecified flaw related to the Rendition Engine. This may allow a remote attacker to bypass access restrictions and gain permission to configure the internal database. No further details have been provided.
|
2011-02-16
|
IBM FileNet Rendition Engine Unspecified Remote Privilege Escalation
|
|
70898
Description:
F-Secure Internet Gatekeeper contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the program fails to require authentication for reading access logs, which will disclose potentially sensitive information to a remote attacker attacker via an admin UI port TCP session.
|
2011-02-15
|
F-Secure Internet Gatekeeper Log File Direct Access
|
|
71773
Description:
Microsoft Windows is prone to an overflow condition. The 'BowserWriteErrorLogEntry' function in the CIFS browser service in 'Mrxsmb.sys' or 'bowser.sys' in Active Directory fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted BROWSER ELECTION message, a remote attacker can potentially execute arbitrary code.
|
2011-02-14
|
Microsoft Windows Common Internet File System (CIFS) Malformed Browser Message Handling Overflow
|
|
70936
Description:
Mailman contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'full name' or 'username' fields in confirmation messages upon submission to the Cgi/confirm.py script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-02-14
|
Mailman Cgi/confirm.py Multiple Parameter XSS
|
|
72528
Description:
OpenLDAP contains a flaw in the 'back-ldap' component. The issue is due to an error within chain.c when a slave server forwards password failures to a master server. With a specially crafted request containing an invalid password, a remote attacker can bypass authentication settings.
|
2011-02-13
|
OpenLDAP back-ldap chain.c Slave Server Invalid Password External-program Authentication Bypass
|
|
72529
Description:
OpenLDAP contains a flaw in the 'back-ndb' component. The issue is due to an error within bind.cpp when handling authentication for a 'rootdn' Distinguished Name (DN). This flaw may allow a remote attacker to bypass authentication settings and perform arbitrary actions.
|
2011-02-13
|
OpenLDAP back-ndb bind.cpp root Distinguished Name (DN) Arbitrary Password Authentication Bypass
|
|
72530
Description:
OpenLDAP contains a flaw in the handling of certain MODRDN requests that may allow a remote denial of service. The issue is due to an error when handling relative Distinguished Name (DN) modification requests (aka MODRDN operation). With a specially crafted request containing an empty value for the OldDN field, a remote attacker can cause the service to crash.
|
2011-02-13
|
OpenLDAP slapd modrdn.c Malformed Relative Distinguished Name (DN) Modification Request (MODRDN) Remote DoS
|
|
70868
Description:
ProFTPD contains a flaw that may allow a remote denial of service. The issue is triggered when the 'mod_sftp' module fails to restrict the maximum payload size of SSH packets, which may be exploited via crafted SSH packets sent to the server to cause a denial of service.
|
2011-02-12
|
ProFTPD mod_sftp Component SSH Payload DoS
|
|
70925
Description:
Apache Continuum contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-02-11
|
Apache Continuum Project Pages Unspecified XSS (2011-0533)
|
|
70960
Description:
MySQL Eventum contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input appended to the URL upon submission to the forgot_password.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-02-11
|
MySQL Eventum forgot_password.php URI XSS
|
|
70961
Description:
MySQL Eventum contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'keywords', 'customer_id', 'status', 'priority', 'category', 'customer_email', 'reporter', 'release' and 'pageRow' parameters upon submission to the list.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-02-11
|
MySQL Eventum list.php Multiple Parameter XSS
|
|
70962
Description:
phpMyAdmin contains a flaw related to the 'PMA_Bookmark_get' function in 'libraries/bookmark.lib.php' failing to properly restrict bookmark queries. This makes it easier for a remote authenticated attacker to cause another user to execute bookmarked SQL queries.
|
2011-02-11
|
phpMyAdmin SQL Query Bookmarks Arbitrary SQL Query Execution
|
|
70924
Description:
Apache Continuum contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for administrative credential modification actions. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-02-11
|
Apache Continuum Multiple Admin Function CSRF
|
|
70872
Description:
ManageEngine ADSelfService Plus contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'searchString', 'searchType' and 'actionID' parameters upon submission to the EmployeeSearch.cc script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-02-11
|
ManageEngine ADSelfService Plus EmployeeSearch.cc Multiple Parameter XSS
|
|
70869
Description:
ManageEngine ADSelfService Plus contains a flaw related to the password reset mechanism. This may allow an attacker to bypass security questions to change an arbitrary user's password by directly accessing the 'accounts/ResetResult' page.
|
2011-02-10
|
ManageEngine ADSelfService Plus accounts/ResetResult Direct Access Security Question Bypass
|
|
70870
Description:
ManageEngine ADSelfService Plus contains a flaw related to the security question verification mechanism. This may allow a remote attacker to eliminate the captcha verification and reduce the required number of questions to one, making it possible to brute force the answer to the question and change an arbitrary user's password.
|
2011-02-10
|
ManageEngine ADSelfService Plus POST Request Manipulation Security Question Weakness
|
|
70904
Description:
A memory corruption flaw exists in Microsoft Office Excel. The program fails to properly handle errors during Office Art record parsing, resulting in memory corruption. With a specially crafted Excel document, a context-dependent attacker can execute arbitrary code.
|
2011-02-10
|
Microsoft Office Excel OfficeArt Container Parsing Memory Corruption
|
|
70852
Description:
Novell iPrint is prone to an overflow condition. The /opt/novell/iprint/bin/ipsmd component of the ilprsrvd service fails to properly sanitize user-supplied input when handling multiple LPR opcodes, which will result in a stack-based buffer overflow. This may allow a remote attacker to potentially execute arbitrary code.
|
2011-02-10
|
Novell iPrint Server LPD ilprsrvd Service Remote Overflow
|
|
70857
Description:
Metasploit Framework on Windows contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when the application is installed with insecure filesystem permissions, allowing a local attacker to create arbitrary files in certain directories, resulting in a privilege escalation which will allow arbitrary code execution with LocalSystem privileges upon the restarting of the 'frameworkPostgreSQL' service.
|
2011-02-10
|
Metasploit Framework on Windows Insecure Filesystem Permissions Local Privilege Escalation
|
|
72574
Description:
(Description Provided by CVE) : FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed VC-1 file.
|
2011-02-10
|
FFmpeg Malformed VC-1 File Handling DoS
|
|
73303
Description:
(Description Provided by CVE) : The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installation to have the same fixed key, which allows remote attackers to gain privileges.
|
2011-02-10
|
Edubuntu Live DVD iTALC Private Keys Regeneration Remote Privilege Escalation
|
|
73766
Description:
(Description Provided by CVE) : Unspecified vulnerability in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to "converson of string encodings" and "inconsistencies in the handling of UTF8 sequences by the user interface."
|
2011-02-10
|
IDA Pro UTF Sequences String Encoding Conversion Unspecified Issue
|
|
70910
Description:
Kerberos contains a flaw that may allow a remote denial of service. The issue is triggered when a NULL pointer dereference occurs in the Key Distribution Center, allowing a remote attacker to use a crafted packet to cause a denial of service.
|
2011-02-09
|
MIT Kerberos 5 Key Distribution Center (KDC) Unspecified DoS
|
|
70909
Description:
Kerberos contains a flaw that may allow a remote denial of service. The issue is triggered when the Key Distribution Center improperly processes certain principal names which causes a NULL pointer dereference error, when an LDAP backend is used, allowing a remote attacker to cause a denial of service via a crafted request.
|
2011-02-09
|
MIT Kerberos 5 Key Distribution Center (KDC) LDAP Backend Principal Name Handling DoS
|
|
70908
Description:
Kerberos contains a flaw that may allow a remote denial of service. The issue is triggered when the unparse implementation in the Key Distribution Center improperly processes certain principal names which trigger backslash escape sequences, when an LDAP backend is used, allowing a remote attacker to cause a denial of service via a crafted request.
|
2011-02-09
|
MIT Kerberos 5 Key Distribution Center (KDC) LDAP Backend Unparse Implementation DoS
|
|
70907
Description:
Kerberos contains a flaw that may allow a remote denial of service. The issue is triggered when the 'do_standalone' function in the KDC database propagation daemon fails to properly handle a worker child process exiting abnormally, allowing a remote attacker to cause a denial of service.
|
2011-02-09
|
MIT Kerberos 5 kpropd do_standalone() Function Unspecified DoS
|
|
70980
Description:
Google Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when the program fails to properly handle anonymous blocks, allowing a remote attacker to cause a stale pointer condition, leading to a denial of service.
|
2011-02-09
|
Google Chrome Anonymous Block Handling Stale Pointer DoS
|