· 10 years ago · Jul 28, 2016, 02:48 AM
1| MITRE CVE - http://cve.mitre.org:
2| [CVE-1999-0144,Candidate,"Denial of service in Qmail by specifying a large number of recipients with the RCPT command.","BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319024&w=2 | BUGTRAQ:19970612 Re: Denial of service (qmail-smtpd) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319029&w=2 | MISC:http://cr.yp.to/qmail/venema.html | MISC:http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html | BID:2237 | URL:http://www.securityfocus.com/bid/2237 | XF:qmail-rcpt | URL:http://xforce.iss.net/static/208.php",Modified (20010301-02)," ACCEPT(4) Baker, Frech, Hill, Meunier | REVIEWING(1) Christey"," Christey> DUPE CVE-1999-0418 and CVE-1999-0250? | Christey> Dan Bernstein, author of Qmail, says that this is not a | vulnerability in qmail because Unix has built-in resource | limits that can restrict the size of a qmail process] other | limits can be specified by the administrator. See | http://cr.yp.to/qmail/venema.html | | Significant discussion of this issue took place on the qmail | list. The fundamental question appears to be whether | application software should set its own limits, or rely | on limits set by the parent operating system (in this case, | UNIX). Also, some people said that the only problem was that | the suggested configuration was not well documented, but this | was refuted by others. | | See the following threads at | http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html | ""Denial of service (qmail-smtpd)"" | ""qmail-dos-2.c, another denial of service"" | ""[PATCH] denial of service"" | ""just another qmail denial-of-service"" | ""the UNIX way"" | ""Time for a reality check"" | | Also see Bugtraq threads on a different vulnerability that | is related to this topic: | BUGTRAQ:19990903 Web servers / possible DOS Attack / mime header flooding | http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html | Baker> http://cr.yp.to/qmail/venema.html | Berstein rejects this as a vulnerability, claiming this is a slander campaign by Wietse Venema. | His page states this is not a qmail problem, rather it is a UNIX problem | that many apps can consume all available memory, and that the administrator | is responsible to set limits in the OS, rather than expect applications to | individually prevent memory exhaustion. CAN 1999-0250 does appear to | be a duplicate of this entry, based on the research I have done so far. | There were two different bugtraq postings, but the second one references | the first, stating that the new exploit uses perl instead of shell scripting | to accomplish the same attack/exploit. | Baker> http://www.securityfocus.com/archive/1/6970 | http://www.securityfocus.com/archive/1/6969 | http://cr.yp.to/qmail/venema.html | | Should probably reject CVE-1999-0250, and add these references to this | Candidate. | Baker> http://www.securityfocus.com/bid/2237 | CHANGE> [Baker changed vote from REVIEWING to ACCEPT] | Christey> qmail-dos-1.c, as published by Wietse Venema (CVE-1999-0250) | in ""BUGTRAQ:19970612 Denial of service (qmail-smtpd)"", does not | use any RCPT commands. Instead, it sends long strings | of ""X"" characters. A followup by ""super@UFO.ORG"" includes | an exploit that claims to do the same thing
3| [CVE-1999-0229,Candidate,"Denial of service in Windows NT IIS server using ..\..","MSKB:Q115052",Modified (19991228-02)," ACCEPT(2) Baker, Shostack | MODIFY(2) Frech, Wall | NOOP(1) Northcutt | REJECT(1) Christey | REVIEWING(1) Levy"," Wall> Denial of service in Windows NT IIS Server 1.0 using ..\... | Source: Microsoft Knowledge Base Article Q115052 - IIS Server. | Frech> XF:http-dotdot (not necessarily IIS?) | Christey> DELREF XF:http-dotdot - it deals with a read/access dot dot | problem. | Christey> This actually looks like XF:iis-dot-dot-crash(1638) | http://xforce.iss.net/static/1638.php | If so, include the version number (2.0) | | CHANGE> [Christey changed vote from REVOTE to REJECT] | Christey> Bill Wall intended to suggest Q155052, but the affected | IIS version there is 1.0] the effect is to read files, | so this sounds like a directory traversal problem, | instead of an inability to process certain strings. | | As a result, this candidate is too general, since it could | apply to 2 different problems, so it should be REJECTed. | Christey> Consider adding BID:2218"
4| [CVE-1999-0250,Candidate,"Denial of service in Qmail through long SMTP commands.","BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319024&w=2 | MISC:http://cr.yp.to/qmail/venema.html | MISC:http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html | XF:qmail-leng",Modified (20010301-01)," ACCEPT(2) Hill, Meunier | MODIFY(1) Frech | REJECT(1) Baker | REVIEWING(1) Christey"," Frech> XF:qmail-rcpt | Christey> DUPE CVE-1999-0418 and CVE-1999-0144? | Christey> Dan Bernstein, author of Qmail, says that this is not a | vulnerability in qmail because Unix has built-in resource | limits that can restrict the size of a qmail process] other | limits can be specified by the administrator. See | http://cr.yp.to/qmail/venema.html | | Significant discussion of this issue took place on the qmail | list. The fundamental question appears to be whether | application software should set its own limits, or rely | on limits set by the parent operating system (in this case, | UNIX). Also, some people said that the only problem was that | the suggested configuration was not well documented, but this | was refuted by others. | | See the following threads at | http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html | ""Denial of service (qmail-smtpd)"" | ""qmail-dos-2.c, another denial of service"" | ""[PATCH] denial of service"" | ""just another qmail denial-of-service"" | ""the UNIX way"" | ""Time for a reality check"" | | Also see Bugtraq threads on a different vulnerability that | is related to this topic: | BUGTRAQ:19990903 Web servers / possible DOS Attack / mime header flooding | http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html | Baker> This appears to be the same vulnerability listed in CAN 1999-0144. In reading | through both bugtraq postings, the one that is referenced by 0144 is | based on a shell code exploit to cause memory exhaustion. The bugtraq | posting referenced by this entry refers explicitly to the prior | posting for 0144, and states that the same effect could be | accomplished by a perl exploit, which was then attached. | Baker> http://www.securityfocus.com/archive/1/6969 CVE-1999-0144 | http://www.securityfocus.com/archive/1/6970 CVE-1999-0250 | | Both references should be added to CVE-1999-0144, and CVE-1999-0250 | should likely be rejected. | CHANGE> [Baker changed vote from REVIEWING to REJECT] | Christey> XF:qmail-leng no longer exists
5| [CVE-1999-0345,Candidate,"Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.","",Proposed (19990728)," ACCEPT(2) Blake, Cole | MODIFY(2) Frech, Wall | NOOP(4) Bishop, Landfield, Northcutt, Ozancin | RECAST(1) Meunier | REJECT(4) Armstrong, Baker, LeBlanc, Levy | REVIEWING(1) Christey"," Wall> Invalid ICMP datagram fragments causes a denial of service in Windows 95 and | Windows NT systems. | Reference: Q154174. | Jolt is also known as sPING, ICMP bug, Icenewk, and Ping of Death. | It is a modified teardrop 2 attack. | Frech> XF:nt-ssping | ADDREF XF:ping-death | ADDREF XF:teardrop-mod | ADDREF XF:mpeix-echo-request-dos | Christey> I can't tell whether the Jolt exploit at: | | http://www.securityfocus.com/templates/archive.pike?list=1&date=1997-06-28&msg=Pine.BSF.3.95q.970629163422.3264A-200000@apollo.tomco.net | | is exploiting any different flaw than teardrop does. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Baker> Jolt (original) is basically just a fragmented oversized ICMP that | kills Win boxes ala Ping of Death. | Teardrop is altering the offset in fragmented tcp packets so that the | end of subsequent fragments is inside first packet... | Teardrop 2 is UDP packets, if I remember right. | Seems like Jolt (original, not jolt 2) is just exploit code that | creates a ping of death (CVE 1999-0128) | Levy> I tend to agree with Baker. | CHANGE> [Armstrong changed vote from REVIEWING to REJECT] | Armstrong> This code does not use fragment overlap. It is simply a large ICMP echo request. | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | LeBlanc> This is a hodge-podge of DoS attacks. Jolt isn't the same | thing as ping of death - POD was an oversized ICMP packet, Jolt froze | Linux and Solaris (and I think not NT), IIRC Jolt2 did get NT boxes. | Teardrop and teardrop2 were related attacks (usually ICMP frag attacks), | but each of these is a distinct vulnerability, affected a discrete group | of systems, and should have distinct CVE numbers. CVE entries should be | precise as to what the problem is. | Meunier> I agree with Leblanc in that Jolt is multi-faceted. Jolt has | characteristics of Ping of Death AND teardrop, but it doesn't do | either exactly. Moreover, it sends a truncated IP fragment. I | disagree with Armstrong] jolt uses overlapping fragments. It's not a | simple ping of death either. It may be that the author's intent was | to construct a ""super attack"" somehow combining elements of other | vulnerabilities to try to make it more potent. In any case it | succeeded in confusing the CVE board :-). | | I notice that Jolt uses echo replies (type 0) instead of echo | requests (to get past firewalls?). Jolt is peculiar in that it also | sends numerous overlapping fragments. The ""Pascal Simulator"" :-) says | it sends: | | - 172 fragments of length 400 with offset starting at 5120 and | increasing by about 47 (odd arithmetic of 5120 OR ((n* 380) >> 3)), | which eventually results in sending fragments inside an already | covered area once ((n* 380) >> 3) is greater than 5120, which occurs | when n is reaches 108. This would look a bit like TearDrop if | fragments were reassembled on-the-fly. | | - 1 fragment such that the total length of all the fragments | is greater than 65535 (my calculation is 172*380 + 418 = 65778
6| [CVE-1999-1050,Candidate,"Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.","BUGTRAQ:19991112 FormHandler.cgi | URL:http://www.securityfocus.com/archive/1/34600 | BUGTRAQ:19991116 Re: FormHandler.cgi | URL:http://www.securityfocus.com/archive/1/34939 | BID:798 | URL:http://www.securityfocus.com/bid/798 | BID:799 | URL:http://www.securityfocus.com/bid/799 | XF:formhandler-cgi-absolute-path(3550) | URL:http://xforce.iss.net/static/3550.php",Proposed (20010912)," ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey"," Christey> Abstraction and definition issue: CD:SF-LOC suggests combining | issues of the same type. Some people refer to ""directory | traversal"" and just mean .. problems] but there are other | issues (specifying an absolute pathname, using C: drive | letters, doing encodings) that, to my way of thinking, are | ""different."" Perhaps this should be split. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I'm interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what ""directory traversal vulnerabilities"" are."
7| [CVE-1999-1307,Candidate,"Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.","BUGTRAQ:19941209 Novell security advisory on sadc, urestore and the suid_exec feature | URL:http://www.dataguard.no/bugtraq/1994_4/0676.html | CIAC:F-06 | URL:http://ciac.llnl.gov/ciac/bulletins/f-06.shtml",Proposed (20010912)," ACCEPT(4) Armstrong, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall"," Frech> XF] novell-unixware-urestore-root(7211)"
8| [CVE-2003-1340,Candidate,"Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php] and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.","BUGTRAQ:20030530 Php-Nuke:users and admins password hashes vulnerability | URL:http://www.securityfocus.com/archive/1/323425 | BUGTRAQ:20070927 Re: [waraxe-2007-SA#056] - Another Sql Injection in NukeSentinel 2.5.11 | URL:http://www.securityfocus.com/archive/1/archive/1/480866/100/0/threaded | SREASON:3185 | URL:http://securityreason.com/securityalert/3185",Assigned (20070930),"None (candidate not yet proposed)",
9| [CVE-2004-0769,Candidate,"Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the ""x"" option but also exploitable through ""l"" and ""v"", and fixed in header.c, a different issue than CVE-2004-0771.","BUGTRAQ:20040616 Re: [SECURITY] [DSA 515-1] New lha packages fix several vulnerabilities] Re: | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108745217504379&w=2 | MISC:http://lw.ftw.zamosc.pl/lha-exploit.txt | FEDORA:FLSA:1833 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1833 | GENTOO:GLSA-200409-13 | URL:http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml | REDHAT:RHSA-2004:440 | URL:http://www.redhat.com/support/errata/RHSA-2004-440.html | CONFIRM:http://bugs.gentoo.org/show_bug.cgi?id=51285 | REDHAT:RHSA-2004:323 | URL:http://www.redhat.com/support/errata/RHSA-2004-323.html | OVAL:oval:org.mitre.oval:def:11047 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11047 | XF:lha-long-pathname-bo(16917) | URL:http://xforce.iss.net/xforce/xfdb/16917",Assigned (20040803),"None (candidate not yet proposed)",
10| [CVE-2004-0790,Candidate,"Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the ""blind connection-reset attack."" NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks] CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.","MISC:http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt | MISC:http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en | MISC:http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html | HP:HPSBTU01210 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=112861397904255&w=2 | HP:SSRT4743 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=112861397904255&w=2 | HP:HPSBUX01164 | URL:http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded | HP:SSRT4884 | URL:http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded | HP:HPSBST02161 | URL:http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded | HP:SSRT061264 | URL:http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded | MS:MS05-019 | URL:http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx | MS:MS06-064 | URL:http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx | SCO:SCOSA-2006.4 | URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt | SUNALERT:57746 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57746-1 | SUNALERT:101658 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101658-1 | BID:13124 | URL:http://www.securityfocus.com/bid/13124 | VUPEN:ADV-2006-3983 | URL:http://www.vupen.com/english/advisories/2006/3983 | OVAL:oval:org.mitre.oval:def:3458 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3458 | OVAL:oval:org.mitre.oval:def:1910 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1910 | OVAL:oval:org.mitre.oval:def:4804 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4804 | OVAL:oval:org.mitre.oval:def:1177 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1177 | OVAL:oval:org.mitre.oval:def:176 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:176 | OVAL:oval:org.mitre.oval:def:211 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:211 | OVAL:oval:org.mitre.oval:def:412 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:412 | OVAL:oval:org.mitre.oval:def:514 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:514 | OVAL:oval:org.mitre.oval:def:53 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:53 | OVAL:oval:org.mitre.oval:def:622 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:622 | SECUNIA:18317 | URL:http://secunia.com/advisories/18317 | SECUNIA:22341 | URL:http://secunia.com/advisories/22341 | SREASON:19 | URL:http://securityreason.com/securityalert/19 | SREASON:57 | URL:http://securityreason.com/securityalert/57",Assigned (20040817),"None (candidate not yet proposed)",
11| [CVE-2004-0791,Candidate,"Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the ""ICMP Source Quench attack."" NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks] CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.","MISC:http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt | MISC:http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en | MISC:http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html | FEDORA:FLSA:157459-1 | URL:http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded | FEDORA:FLSA:157459-2 | URL:http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded | HP:HPSBTU01210 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=112861397904255&w=2 | HP:SSRT4743 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=112861397904255&w=2 | HP:SSRT4884 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=112861397904255&w=2 | HP:HPSBUX01164 | URL:http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded | REDHAT:RHSA-2005:016 | URL:http://www.redhat.com/support/errata/RHSA-2005-016.html | REDHAT:RHSA-2005:017 | URL:http://www.redhat.com/support/errata/RHSA-2005-017.html | REDHAT:RHSA-2005:043 | URL:http://www.redhat.com/support/errata/RHSA-2005-043.html | SCO:SCOSA-2006.4 | URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt | SUNALERT:57746 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57746-1 | SUNALERT:101658 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101658-1 | BID:13124 | URL:http://www.securityfocus.com/bid/13124 | OVAL:oval:org.mitre.oval:def:1112 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1112 | OVAL:oval:org.mitre.oval:def:184 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:184 | OVAL:oval:org.mitre.oval:def:464 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:464 | OVAL:oval:org.mitre.oval:def:596 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:596 | OVAL:oval:org.mitre.oval:def:688 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:688 | OVAL:oval:org.mitre.oval:def:726 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:726 | OVAL:oval:org.mitre.oval:def:10228 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10228 | SECUNIA:18317 | URL:http://secunia.com/advisories/18317 | SREASON:19 | URL:http://securityreason.com/securityalert/19 | SREASON:57 | URL:http://securityreason.com/securityalert/57",Assigned (20040817),"None (candidate not yet proposed)",
12| [CVE-2004-0842,Candidate,"Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from ""memory corruption"") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the ""<STYLE>@] /*"" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the ""CSS Heap Memory Corruption Vulnerability.""","FULLDISC:20040723 Crash IE with 11 bytes
13| [CVE-2004-1060,Candidate,"Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP (""Fragmentation Needed and Don't Fragment was Set"") packets with a low next-hop MTU value, aka the ""Path MTU discovery attack."" NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks] CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.","MISC:http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en | MISC:http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html | CISCO:20050412 Crafted ICMP Messages Can Cause Denial of Service | URL:http://www.cisco.com/warp/public/707/cisco-sa-20050412-icmp.shtml | HP:HPSBTU01210 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=112861397904255&w=2 | HP:SSRT4743 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=112861397904255&w=2 | HP:SSRT4884 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=112861397904255&w=2 | HP:HPSBUX01164 | URL:http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded | MS:MS05-019 | URL:http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx | SCO:SCOSA-2006.4 | URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt | BID:13124 | URL:http://www.securityfocus.com/bid/13124 | OVAL:oval:org.mitre.oval:def:2188 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2188 | OVAL:oval:org.mitre.oval:def:3826 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3826 | OVAL:oval:org.mitre.oval:def:780 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:780 | OVAL:oval:org.mitre.oval:def:181 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:181 | OVAL:oval:org.mitre.oval:def:196 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:196 | OVAL:oval:org.mitre.oval:def:405 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:405 | OVAL:oval:org.mitre.oval:def:651 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:651 | OVAL:oval:org.mitre.oval:def:899 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:899 | OVAL:oval:org.mitre.oval:def:5386 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5386 | SECUNIA:18317 | URL:http://secunia.com/advisories/18317 | SREASON:19 | URL:http://securityreason.com/securityalert/19 | SREASON:57 | URL:http://securityreason.com/securityalert/57",Assigned (20041123),"None (candidate not yet proposed)",
14| [CVE-2005-1635,Candidate,"JGS-XA JGS-Portal 3.0.2 and earlier allows remote attackers to obtain the full server path via direct requests to (1) jgs_portal_ref.php, (2) jgs_portal_land.php, (3) jgs_portal_log.php, (4) jgs_portal_global_sponsor.php, (5) jgs_portal_global.php, (6) jgs_portal_system.php, (7) jgs_portal_views.php] or multiple files in the jgs_portal_include directory, including (8) jgs_portal_boardmenue.php, (9) jgs_portal_forenliste.php, (10) jgs_portal_geburtstag.php, (11) jgs_portal_guckloch.php, (12) jgs_portal_kalender.php, (13) jgs_portal_letztethemen.php, (14) jgs_portal_links.php, (15) jgs_portal_neustemember.php, (16) jgs_portal_newsboard.php, (17) jgs_portal_online.php, (18) jgs_portal_pn.php, (19) jgs_portal_portalmenue.php, (20) jgs_portal_styles.php, (21) jgs_portal_suchen.php, (22) jgs_portal_team.php, (23) jgs_portal_topforen.php, (24) jgs_portal_topposter.php, (25) jgs_portal_umfrage.php, (26) jgs_portal_useravatar.php, (27) jgs_portal_waronline.php, (28) jgs_portal_woonline.php, or (29) jgs_portal_zufallsavatar.php.","BUGTRAQ:20050516 [SePro Bugtraq] WBB Portal - JGS-Portal <= 3.0.2 - Multiple Vulnerabilities (09.05.05) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=111627681218415&w=2",Assigned (20050517),"None (candidate not yet proposed)",
15| [CVE-2005-3180,Candidate,"The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information.","BUGTRAQ:20051012 Linux Orinoco drivers information leakage | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=112914754708402&w=2 | CONFIRM:http://www.kernel.org/hg/linux-2.6/?cmd=changeset] node=feecb2ffde28639e60ede769c6f817dc536c677b | DEBIAN:DSA-1017 | URL:http://www.debian.org/security/2006/dsa-1017 | FEDORA:FEDORA-2005-1007 | URL:http://www.securityfocus.com/advisories/9549 | FEDORA:FLSA:157459-1 | URL:http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded | FEDORA:FLSA:157459-2 | URL:http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded | FEDORA:FLSA:157459-3 | URL:http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded | MANDRAKE:MDKSA-2005:218 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 | MANDRAKE:MDKSA-2005:219 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 | MANDRAKE:MDKSA-2005:220 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:220 | MANDRIVA:MDKSA-2005:219 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 | MANDRIVA:MDKSA-2005:220 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:220 | MANDRIVA:MDKSA-2005:235 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:235 | REDHAT:RHSA-2005:808 | URL:http://www.redhat.com/support/errata/RHSA-2005-808.html | REDHAT:RHSA-2006:0140 | URL:http://www.redhat.com/support/errata/RHSA-2006-0140.html | REDHAT:RHSA-2006:0190 | URL:http://www.redhat.com/support/errata/RHSA-2006-0190.html | REDHAT:RHSA-2006:0191 | URL:http://www.redhat.com/support/errata/RHSA-2006-0191.html | SUSE:SUSE-SA:2005:067 | URL:http://www.securityfocus.com/advisories/9806 | SUSE:SUSE-SA:2005:068 | URL:http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded | UBUNTU:USN-219-1 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-219-1 | BID:15085 | URL:http://www.securityfocus.com/bid/15085 | OVAL:oval:org.mitre.oval:def:11332 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11332 | SECUNIA:17364 | URL:http://secunia.com/advisories/17364 | SECUNIA:17917 | URL:http://secunia.com/advisories/17917 | SECUNIA:17918 | URL:http://secunia.com/advisories/17918 | SECUNIA:18562 | URL:http://secunia.com/advisories/18562 | SECUNIA:18684 | URL:http://secunia.com/advisories/18684 | SECUNIA:17114 | URL:http://secunia.com/advisories/17114 | SECUNIA:17280 | URL:http://secunia.com/advisories/17280 | SECUNIA:17826 | URL:http://secunia.com/advisories/17826 | SECUNIA:19374 | URL:http://secunia.com/advisories/19374 | SREASON:75 | URL:http://securityreason.com/securityalert/75",Assigned (20051011),"None (candidate not yet proposed)",
16| [CVE-2005-3921,Candidate,"Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump] or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.","IDEFENSE:20060117 Cisco Systems IOS 11 Web Service CDP Status Page Code Injection Vulnerability | URL:http://www.idefense.com/intelligence/vulnerabilities/display.php?id=372 | BUGTRAQ:20051128 - Cisco IOS HTTP Server code injection/execution vulnerability- | URL:http://www.securityfocus.com/archive/1/archive/1/417916/100/0/threaded | MISC:http://www.infohacking.com/INFOHACKING_RESEARCH/Our_Advisories/cisco/index.html | CISCO:20051201 IOS HTTP Server Command Injection Vulnerability | URL:http://www.cisco.com/warp/public/707/cisco-sa-20051201-http.shtml | BID:15602 | URL:http://www.securityfocus.com/bid/15602 | BID:16291 | URL:http://www.securityfocus.com/bid/16291 | OVAL:oval:org.mitre.oval:def:5867 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5867 | VUPEN:ADV-2005-2657 | URL:http://www.vupen.com/english/advisories/2005/2657 | SECTRACK:1015275 | URL:http://securitytracker.com/id?1015275 | SECUNIA:17780 | URL:http://secunia.com/advisories/17780 | SECUNIA:18528 | URL:http://secunia.com/advisories/18528 | SREASON:227 | URL:http://securityreason.com/securityalert/227",Assigned (20051130),"None (candidate not yet proposed)",
17| [CVE-2005-4667,Candidate,"Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.","FULLDISC:20051219 Unzip *ALL* verisons ] )) | URL:http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0930.html | CONFIRM:http://www.info-zip.org/FAQ.html | DEBIAN:DSA-1012 | URL:http://www.debian.org/security/2006/dsa-1012 | FEDORA:FLSA:180159 | URL:http://www.securityfocus.com/archive/1/archive/1/430300/100/0/threaded | MANDRIVA:MDKSA-2006:050 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:050 | REDHAT:RHSA-2007:0203 | URL:http://www.redhat.com/support/errata/RHSA-2007-0203.html | TRUSTIX:2006-0006 | URL:http://www.trustix.org/errata/2006/0006 | UBUNTU:USN-248-1 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-248-1 | UBUNTU:USN-248-2 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-248-2 | BID:15968 | URL:http://www.securityfocus.com/bid/15968 | OSVDB:22400 | URL:http://www.osvdb.org/22400 | OVAL:oval:org.mitre.oval:def:11252 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11252 | SECUNIA:25098 | URL:http://secunia.com/advisories/25098",Assigned (20060125),"None (candidate not yet proposed)",
18| [CVE-2006-0096,Candidate,"wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors. NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN] thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.","CONFIRM:http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git
19| [CVE-2006-0125,Candidate,"Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.","BID:16166 | URL:http://www.securityfocus.com/bid/16166 | VUPEN:ADV-2006-0053 | URL:http://www.vupen.com/english/advisories/2006/0053 | OSVDB:22228 | URL:http://www.osvdb.org/22228 | SECUNIA:18163 | URL:http://secunia.com/advisories/18163",Assigned (20060109),"None (candidate not yet proposed)",
20| [CVE-2006-0245,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php] and the (8) username field in a login action in index.php. NOTE: the cart.php/redir and index.php/searchStr vectors are already covered by CVE-2005-3152.","MISC:http://bugs.cubecart.com/?do=details&id=459 | MISC:http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html | BID:16259 | URL:http://www.securityfocus.com/bid/16259 | VUPEN:ADV-2006-0227 | URL:http://www.vupen.com/english/advisories/2006/0227 | OSVDB:22471 | URL:http://www.osvdb.org/22471 | SECUNIA:18519 | URL:http://secunia.com/advisories/18519 | XF:cubecart-index-script-xss(24177) | URL:http://xforce.iss.net/xforce/xfdb/24177",Assigned (20060118),"None (candidate not yet proposed)",
21| [CVE-2006-0448,Candidate,"Multiple directory traversal vulnerabilities in (1) EPSTIMAP4S.EXE and (2) SPA-IMAP4S.EXE in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allow remote attackers to (a) list arbitrary directories or cause a denial of service via the LIST command] or create arbitrary files via the (b) APPEND, (c) COPY, or (d) RENAME commands.","MISC:http://secunia.com/secunia_research/2006-1/advisory/ | BID:16379 | URL:http://www.securityfocus.com/bid/16379 | VUPEN:ADV-2006-0318 | URL:http://www.vupen.com/english/advisories/2006/0318 | OSVDB:22764 | URL:http://www.osvdb.org/22764 | OSVDB:22765 | URL:http://www.osvdb.org/22765 | SECUNIA:18480 | URL:http://secunia.com/advisories/18480 | XF:epost-append-copy-rename-file-creation(24336) | URL:http://xforce.iss.net/xforce/xfdb/24336 | XF:epost-imap-list-directory-traversal(24335) | URL:http://xforce.iss.net/xforce/xfdb/24335 | XF:epost--append-copy-rename-file-creation(24336) | URL:http://xforce.iss.net/xforce/xfdb/24336",Assigned (20060126),"None (candidate not yet proposed)",
22| [CVE-2006-0517,Candidate,"Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve parameters to forum.php3] (4) unspecified vectors related to ""session handling""
23| [CVE-2006-0732,Candidate,"Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the grace period has ended. NOTE: SAP Business Connector is an OEM version of webMethods Integration Server. webMethods states that this issue can only occur when the product is installed as root/admin, and if the attacker has access to a general purpose port] however, both are discouraged in the documentation. In addition, the attacker must already have acquired administrative privileges through other means.","BUGTRAQ:20060215 CYBSEC - Security Pre-Advisory: Arbitrary File Read/Delete in SAPBC | URL:http://www.securityfocus.com/archive/1/archive/1/425048/100/0/threaded | MISC:http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf | BUGTRAQ:20060515 CYBSEC - Security Advisory: Arbitrary File Read/Delete in SAP BC(Business Connector) | URL:http://www.securityfocus.com/archive/1/archive/1/434014/30/4980/threaded | MISC:http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf | BID:16668 | URL:http://www.securityfocus.com/bid/16668 | VUPEN:ADV-2006-0611 | URL:http://www.vupen.com/english/advisories/2006/0611 | SECTRACK:1015639 | URL:http://securitytracker.com/id?1015639 | SECTRACK:1016122 | URL:http://securitytracker.com/id?1016122 | SECTRACK:1016090 | URL:http://securitytracker.com/id?1016090 | SECUNIA:18880 | URL:http://secunia.com/advisories/18880",Assigned (20060216),"None (candidate not yet proposed)",
24| [CVE-2006-0755,Candidate,"** DISPUTED ** Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php] and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product.","BUGTRAQ:20060214 dotproject <= 2.0.1 remote code execution | URL:http://www.securityfocus.com/archive/1/archive/1/424957/100/0/threaded | BUGTRAQ:20060215 Re: dotproject <= 2.0.1 remote code execution | URL:http://www.securityfocus.com/archive/1/425285/100/0/threaded | BID:16648 | URL:http://www.securityfocus.com/bid/16648 | VUPEN:ADV-2006-0604 | URL:http://www.vupen.com/english/advisories/2006/0604 | OSVDB:23209 | URL:http://www.osvdb.org/23209 | OSVDB:23212 | URL:http://www.osvdb.org/23212 | OSVDB:23210 | URL:http://www.osvdb.org/23210 | OSVDB:23211 | URL:http://www.osvdb.org/23211 | OSVDB:23213 | URL:http://www.osvdb.org/23213 | OSVDB:23214 | URL:http://www.osvdb.org/23214 | OSVDB:23215 | URL:http://www.osvdb.org/23215 | OSVDB:23216 | URL:http://www.osvdb.org/23216 | OSVDB:23217 | URL:http://www.osvdb.org/23217 | OSVDB:23218 | URL:http://www.osvdb.org/23218 | OSVDB:23219 | URL:http://www.osvdb.org/23219 | SECUNIA:18879 | URL:http://secunia.com/advisories/18879 | XF:dotproject-multiple-basedir-file-include(24738) | URL:http://xforce.iss.net/xforce/xfdb/24738",Assigned (20060218),"None (candidate not yet proposed)",
25| [CVE-2006-0909,Candidate,"Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) class_db.php, (5) class_db_mysql.php, and (6) class_xml.php in the ips_kernel/ directory] (7) mysql_admin_queries.php, (8) mysql_extra_queries.php, (9) mysql_queries.php, and (10) mysql_subsm_queries.php in the sources/sql directory
26| [CVE-2006-0921,Candidate,"Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.","BUGTRAQ:20060223 NSA Group Security Advisory NSAG-¹] 195-23.02.2006 Vulnerability FCKeditor 2.0 FC | URL:http://www.securityfocus.com/archive/1/archive/1/425937/100/0/threaded | BUGTRAQ:20060519 Re: NSA Group Security Advisory NSAG-¹
27| [CVE-2006-0922,Candidate,"CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php.","BUGTRAQ:20060223 NSA Group Security Advisory NSAG-¹] 197-23.02.2006 Vulnerability CubeCart 3.0.0 ? 3.0.6 | URL:http://www.securityfocus.com/archive/1/archive/1/425931/100/0/threaded | MISC:http://www.cubecart.com/site/forums/index.php?showtopic=14817 | MISC:http://www.cubecart.com/site/forums/index.php?showtopic=14825 | MISC:http://www.cubecart.com/site/forums/index.php?showtopic=14960 | MISC:http://www.cubecart.com/site/forums/index.php?showtopic=14972 | MISC:http://www.nsag.ru/vuln/892.html | CONFIRM:http://www.cubecart.com/site/forums/index.php?showtopic=14704 | BID:16796 | URL:http://www.securityfocus.com/bid/16796 | SREASON:482 | URL:http://securityreason.com/securityalert/482 | XF:cubecart-connector-file-include(24883) | URL:http://xforce.iss.net/xforce/xfdb/24883",Assigned (20060228),"None (candidate not yet proposed)",
28| [CVE-2006-0936,Candidate,"Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.","BUGTRAQ:20060225 NSA Group Security Advisory NSAG-¹] 202-25.02.2006 Vulnerability WEBSITE GENERATOR 3.3 | URL:http://www.securityfocus.com/archive/1/archive/1/426077/100/0/threaded | MISC:http://nsag.ru/vuln/894.html | BID:16823 | URL:http://www.securityfocus.com/bid/16823 | SECUNIA:19014 | URL:http://secunia.com/advisories/19014",Assigned (20060228),"None (candidate not yet proposed)",
29| [CVE-2006-0986,Candidate,"WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory] and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory
30| [CVE-2006-1024,Candidate,"SQL injection vulnerability in MgrLogin.asp in Addsoft StoreBot 2005 Professional allows remote attackers to execute arbitrary SQL commands via the Pwd parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:16897 | URL:http://www.securityfocus.com/bid/16897 | VUPEN:ADV-2006-0784 | URL:http://www.vupen.com/english/advisories/2006/0784 | OSVDB:23575 | URL:http://www.osvdb.org/23575 | SECUNIA:19019 | URL:http://secunia.com/advisories/19019 | XF:storebot-mgrlogin-sql-injection(24987) | URL:http://xforce.iss.net/xforce/xfdb/24987",Assigned (20060306),"None (candidate not yet proposed)",
31| [CVE-2006-1025,Candidate,"Cross-site scripting (XSS) vulnerability in manage.asp in Addsoft StoreBot 2002 Standard allows remote attackers to inject arbitrary web script or HTML via the ShipMethod parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:16898 | URL:http://www.securityfocus.com/bid/16898 | VUPEN:ADV-2006-0785 | URL:http://www.vupen.com/english/advisories/2006/0785 | OSVDB:23574 | URL:http://www.osvdb.org/23574 | SECUNIA:19060 | URL:http://secunia.com/advisories/19060 | XF:storebot-manage-xss(24986) | URL:http://xforce.iss.net/xforce/xfdb/24986",Assigned (20060306),"None (candidate not yet proposed)",
32| [CVE-2006-1034,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. The second vector might not be XSS.","BID:16843 | URL:http://www.securityfocus.com/bid/16843",Assigned (20060307),"None (candidate not yet proposed)",
33| [CVE-2006-1050,Candidate,"** DISPUTED ** Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. NOTE: the vendor has disputed this vulnerability, stating that ""The kwikpay.mdb file supplied with kwikpay is a template for the database structure of user databases created by kwikpay and to store a demonstration payroll. It does not contain any sensitive user information. When a user payroll database is opened, the encryption of the database is checked and if the database is not encrypted, the user is prompted to encrypt the database, but the choice is the customers.""","OSVDB:23617 | URL:http://www.osvdb.org/23617 | SECUNIA:19075 | URL:http://secunia.com/advisories/19075 | XF:kwikpay-payroll-insecure-permissions(25114) | URL:http://xforce.iss.net/xforce/xfdb/25114",Assigned (20060307),"None (candidate not yet proposed)",
34| [CVE-2006-1104,Candidate,"Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the showimage parameter in index.php] and the (2) USER_AGENT, (3) HTTP_REFERER, and (4) HTTP_HOST HTTP header fields as used in the book_vistor function in includes/functions.php. NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.","BUGTRAQ:20060304 Pixel Post Multiple Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/426764/100/0/threaded | MISC:http://www.neosecurityteam.net/index.php?action=advisories&id=19 | MISC:http://forum.pixelpost.org/showthread.php?t=3535 | BID:16964 | URL:http://www.securityfocus.com/bid/16964 | VUPEN:ADV-2006-0823 | URL:http://www.vupen.com/english/advisories/2006/0823 | XF:pixelpost-functions-sql-injection(25046) | URL:http://xforce.iss.net/xforce/xfdb/25046 | XF:pixelpost-index-sql-injection(25044) | URL:http://xforce.iss.net/xforce/xfdb/25044",Assigned (20060309),"None (candidate not yet proposed)",
35| [CVE-2006-1235,Candidate,"Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable. NOTE: the initial disclosure for this issue indicated that the researcher was unable to prove this issue] however, this might have been due to certain behaviors of rmdir.","BUGTRAQ:20060306 histhost v1.0.0 xss and possible rmdir | URL:http://www.securityfocus.com/archive/1/archive/1/426931/100/0/threaded | BUGTRAQ:20060314 Re: histhost v1.0.0 xss and possible rmdir | URL:http://www.securityfocus.com/archive/1/archive/1/427631/100/0/threaded | SECUNIA:19155 | URL:http://secunia.com/advisories/19155 | XF:hithost-deleteuser-directory-deletion(25106) | URL:http://xforce.iss.net/xforce/xfdb/25106",Assigned (20060314),"None (candidate not yet proposed)",
36| [CVE-2006-1278,Candidate,"SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php] (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.","BUGTRAQ:20060324 [eVuln] @1 File Store Multiple XSS and SQL Injection Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/428659/100/0/threaded | MILW0RM:6040 | URL:http://www.milw0rm.com/exploits/6040 | MISC:http://evuln.com/vulns/95/summary.html | VIM:20090825 @1 File Store PRO SQL injection - the old gray dupe | URL:http://www.attrition.org/pipermail/vim/2009-August/002246.html | BID:17090 | URL:http://www.securityfocus.com/bid/17090 | BID:30182 | URL:http://www.securityfocus.com/bid/30182 | OSVDB:47017 | URL:http://osvdb.org/47017 | OSVDB:47018 | URL:http://osvdb.org/47018 | SECUNIA:31063 | URL:http://secunia.com/advisories/31063 | VUPEN:ADV-2006-0943 | URL:http://www.vupen.com/english/advisories/2006/0943 | OSVDB:23851 | URL:http://www.osvdb.org/23851 | OSVDB:23852 | URL:http://www.osvdb.org/23852 | OSVDB:23853 | URL:http://www.osvdb.org/23853 | OSVDB:23854 | URL:http://www.osvdb.org/23854 | OSVDB:23855 | URL:http://www.osvdb.org/23855 | OSVDB:23856 | URL:http://www.osvdb.org/23856 | OSVDB:23857 | URL:http://www.osvdb.org/23857 | OSVDB:23858 | URL:http://www.osvdb.org/23858 | OSVDB:23859 | URL:http://www.osvdb.org/23859 | OSVDB:23860 | URL:http://www.osvdb.org/23860 | OSVDB:23861 | URL:http://www.osvdb.org/23861 | OSVDB:23862 | URL:http://www.osvdb.org/23862 | OSVDB:23863 | URL:http://www.osvdb.org/23863 | OSVDB:23864 | URL:http://www.osvdb.org/23864 | OSVDB:24106 | URL:http://www.osvdb.org/24106 | SECTRACK:1015826 | URL:http://securitytracker.com/id?1015826 | SECUNIA:19224 | URL:http://secunia.com/advisories/19224 | SREASON:619 | URL:http://securityreason.com/securityalert/619 | XF:filestore-multiple-sql-injection(25183) | URL:http://xforce.iss.net/xforce/xfdb/25183 | XF:filestorepro-download-file-include(43724) | URL:http://xforce.iss.net/xforce/xfdb/43724 | XF:filestorepro-id-sql-injection(43718) | URL:http://xforce.iss.net/xforce/xfdb/43718",Assigned (20060318),"None (candidate not yet proposed)",
37| [CVE-2006-1353,Candidate,"Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the downloadid parameter in download_click.asp and (2) content_ID parameter in news/News_Item.asp] authenticated administrators can also conduct attacks via (3) user_id parameter to users/add_edit_user.asp, (4) bannerid parameter to banner_adds/banner_add_edit.asp, (5) cat_id parameter to categories/add_edit_cat.asp, (6) Content_ID parameter to News/add_edit_news.asp, (7) download_id parameter to downloads/add_edit_download.asp, (8) Poll_ID parameter to poll/add_edit_poll.asp, (9) contactid parameter to contactus/contactus_add_edit.asp, (10) sortby parameter to poll/poll_list.asp, and (11) unspecified inputs to downloads/add_edit_download.asp.","BUGTRAQ:20060321 ASPPortal <= 3.1.1 Multiple Remote SQL Injection Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/428355/100/0/threaded | BUGTRAQ:20060322 Re: [SPAM:] - ASPPortal <= 3.1.1 Multiple Remote SQL Injection Vulnerabilities - Email has different SMTP TO: and MIME TO: fields in the email addresses | URL:http://www.securityfocus.com/archive/1/archive/1/428615/100/0/threaded | FULLDISC:20060321 ASPPortal <= 3.1.1 Multiple Remote SQL Injection Vulnerabilities | URL:http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1402.html | FULLDISC:20060322 Re: [SPAM:] - ASPPortal <= 3.1.1 Multiple Remote SQL Injection Vulnerabilities - Email has different SMTP TO: and MIME TO: fields in the email addresses | URL:http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1431.html | MISC:http://www.nukedx.com/?viewdoc=21 | MILW0RM:1597 | URL:http://www.milw0rm.com/exploits/1597 | BID:17174 | URL:http://www.securityfocus.com/bid/17174 | VUPEN:ADV-2006-1014 | URL:http://www.vupen.com/english/advisories/2006/1014 | OSVDB:24020 | URL:http://www.osvdb.org/24020 | OSVDB:24084 | URL:http://www.osvdb.org/24084 | OSVDB:24085 | URL:http://www.osvdb.org/24085 | OSVDB:24086 | URL:http://www.osvdb.org/24086 | OSVDB:24087 | URL:http://www.osvdb.org/24087 | OSVDB:24088 | URL:http://www.osvdb.org/24088 | OSVDB:24089 | URL:http://www.osvdb.org/24089 | OSVDB:24090 | URL:http://www.osvdb.org/24090 | OSVDB:24091 | URL:http://www.osvdb.org/24091 | OSVDB:24092 | URL:http://www.osvdb.org/24092 | SECUNIA:19286 | URL:http://secunia.com/advisories/19286 | SREASON:608 | URL:http://securityreason.com/securityalert/608 | XF:aspportal-multiple-aspscripts-sql-injection(25346) | URL:http://xforce.iss.net/xforce/xfdb/25346",Assigned (20060321),"None (candidate not yet proposed)",
38| [CVE-2006-1542,Candidate,"Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a ""stack overflow,"" and possibly gain privileges, by running a script from a current working directory that has a long name, related to the realpath function. NOTE: this might not be a vulnerability. However, the fact that it appears in a programming language interpreter could mean that some applications are affected, although attack scenarios might be limited because the attacker might already need to cross privilege boundaries to cause an exploitable program to be placed in a directory with a long name] or, depending on the method that Python uses to determine the current working directory, setuid applications might be affected.","MILW0RM:1591 | URL:http://milw0rm.com/exploits/1591 | MISC:http://www.gotfault.net/research/exploit/gexp-python.py | REDHAT:RHSA-2008:0629 | URL:http://www.redhat.com/support/errata/RHSA-2008-0629.html | SECUNIA:31492 | URL:http://secunia.com/advisories/31492",Assigned (20060330),"None (candidate not yet proposed)",
39| [CVE-2006-1642,Candidate,"Cross-site scripting (XSS) vulnerability in Interact 2.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) the search_terms parameter to (a) search.php, and (2) the first_name, (3) last_name, (4) email, (5) password, and (6) confirm_password parameters to (b) userinput.php. NOTE: the provenance of this information is unknown] the details are obtained from third party. In addition, the lack of precision in the third party descriptions makes it unclear whether the named vectors are correct.","VUPEN:ADV-2006-1244 | URL:http://www.vupen.com/english/advisories/2006/1244 | OSVDB:24389 | URL:http://www.osvdb.org/24389 | OSVDB:24461 | URL:http://www.osvdb.org/24461 | SECUNIA:19488 | URL:http://secunia.com/advisories/19488 | XF:interact-search-xss(25652) | URL:http://xforce.iss.net/xforce/xfdb/25652",Assigned (20060406),"None (candidate not yet proposed)",
40| [CVE-2006-1741,Candidate,"Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) ""using a modal alert to suspend an event handler while a new page is being loaded"", (2) using eval(), and using certain variants involving (3) ""new Script] "" and (4) using window.__proto__ to extend eval, aka ""cross-site JavaScript injection"".","CONFIRM:http://www.mozilla.org/security/announce/2006/mfsa2006-09.html | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm | DEBIAN:DSA-1044 | URL:http://www.debian.org/security/2006/dsa-1044 | DEBIAN:DSA-1046 | URL:http://www.debian.org/security/2006/dsa-1046 | DEBIAN:DSA-1051 | URL:http://www.debian.org/security/2006/dsa-1051 | FEDORA:FEDORA-2006-410 | URL:http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html | FEDORA:FEDORA-2006-411 | URL:http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html | FEDORA:FLSA:189137-1 | URL:http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded | FEDORA:FLSA:189137-2 | URL:http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded | GENTOO:GLSA-200604-12 | URL:http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml | GENTOO:GLSA-200604-18 | URL:http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml | GENTOO:GLSA-200605-09 | URL:http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml | HP:HPSBUX02122 | URL:http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded | HP:SSRT061158 | URL:http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded | MANDRIVA:MDKSA-2006:076 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:076 | MANDRIVA:MDKSA-2006:078 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:078 | REDHAT:RHSA-2006:0328 | URL:http://www.redhat.com/support/errata/RHSA-2006-0328.html | REDHAT:RHSA-2006:0329 | URL:http://www.redhat.com/support/errata/RHSA-2006-0329.html | REDHAT:RHSA-2006:0330 | URL:http://www.redhat.com/support/errata/RHSA-2006-0330.html | SCO:SCOSA-2006.26 | URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt | SGI:20060404-01-U | URL:ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc | SUNALERT:102550 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1 | SUNALERT:228526 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1 | SUSE:SUSE-SA:2006:022 | URL:http://www.novell.com/linux/security/advisories/2006_04_25.html | SUSE:SUSE-SA:2006:021 | URL:http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html | SUSE:SUSE-SA:2006:004 | URL:http://www.novell.com/linux/security/advisories/2006_04_25.html | UBUNTU:USN-275-1 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-275-1 | UBUNTU:USN-276-1 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-276-1 | UBUNTU:USN-271-1 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-271-1 | OVAL:oval:org.mitre.oval:def:9167 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9167 | VUPEN:ADV-2006-1356 | URL:http://www.vupen.com/english/advisories/2006/1356 | OVAL:oval:org.mitre.oval:def:1855 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1855 | SECUNIA:19631 | URL:http://secunia.com/advisories/19631 | SECUNIA:19759 | URL:http://secunia.com/advisories/19759 | SECUNIA:19821 | URL:http://secunia.com/advisories/19821 | SECUNIA:19811 | URL:http://secunia.com/advisories/19811 | SECUNIA:19823 | URL:http://secunia.com/advisories/19823 | SECUNIA:19852 | URL:http://secunia.com/advisories/19852 | SECUNIA:19862 | URL:http://secunia.com/advisories/19862 | SECUNIA:19863 | URL:http://secunia.com/advisories/19863 | SECUNIA:19902 | URL:http://secunia.com/advisories/19902 | SECUNIA:19950 | URL:http://secunia.com/advisories/19950 | SECUNIA:19941 | URL:http://secunia.com/advisories/19941 | SECUNIA:19714 | URL:http://secunia.com/advisories/19714 | SECUNIA:19721 | URL:http://secunia.com/advisories/19721 | SECUNIA:19746 | URL:http://secunia.com/advisories/19746 | SECUNIA:21033 | URL:http://secunia.com/advisories/21033 | SECUNIA:21622 | URL:http://secunia.com/advisories/21622 | SECUNIA:19696 | URL:http://secunia.com/advisories/19696 | SECUNIA:19729 | URL:http://secunia.com/advisories/19729 | SECUNIA:19780 | URL:http://secunia.com/advisories/19780 | SECUNIA:20051 | URL:http://secunia.com/advisories/20051 | XF:mozilla-eventhandler-xss(25806) | URL:http://xforce.iss.net/xforce/xfdb/25806",Assigned (20060412),"None (candidate not yet proposed)",
41| [CVE-2006-1782,Candidate,"Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig] or ""insecurely"" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.","CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2006-122.htm | SUNALERT:102113 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102113-1 | BID:17479 | URL:http://www.securityfocus.com/bid/17479 | VUPEN:ADV-2006-1334 | URL:http://www.vupen.com/english/advisories/2006/1334 | OSVDB:24563 | URL:http://www.osvdb.org/24563 | OSVDB:24564 | URL:http://www.osvdb.org/24564 | OSVDB:24565 | URL:http://www.osvdb.org/24565 | OSVDB:24566 | URL:http://www.osvdb.org/24566 | OSVDB:24567 | URL:http://www.osvdb.org/24567 | OSVDB:24568 | URL:http://www.osvdb.org/24568 | OVAL:oval:org.mitre.oval:def:1840 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1840 | SECTRACK:1015903 | URL:http://securitytracker.com/id?1015903 | SECUNIA:19638 | URL:http://secunia.com/advisories/19638 | SECUNIA:21493 | URL:http://secunia.com/advisories/21493 | XF:solaris-ldap2-password-disclosure(25747) | URL:http://xforce.iss.net/xforce/xfdb/25747",Assigned (20060413),"None (candidate not yet proposed)",
42| [CVE-2006-1900,Candidate,"Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element] and via other unspecified attack vectors consisting of ""dozens of possible snippets.""","BUGTRAQ:20060412 [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4 | URL:http://www.securityfocus.com/archive/1/archive/1/430877/100/0/threaded | BUGTRAQ:20060412 [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4 #2 | URL:http://www.securityfocus.com/archive/1/archive/1/430879/100/0/threaded | MISC:http://morph3us.org/advisories/20060412-amaya-94.txt | MISC:http://morph3us.org/advisories/20060412-amaya-94-2.txt | BID:17507 | URL:http://www.securityfocus.com/bid/17507 | VUPEN:ADV-2006-1351 | URL:http://www.vupen.com/english/advisories/2006/1351 | OSVDB:24623 | URL:http://www.osvdb.org/24623 | OSVDB:24624 | URL:http://www.osvdb.org/24624 | SECUNIA:19670 | URL:http://secunia.com/advisories/19670 | XF:amaya-various-attribute-bo(25791) | URL:http://xforce.iss.net/xforce/xfdb/25791",Assigned (20060420),"None (candidate not yet proposed)",
43| [CVE-2006-1937,Candidate,"Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors] and (7) the statistics counter.","CONFIRM:http://www.ethereal.com/appnotes/enpa-sa-00023.html | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm | DEBIAN:DSA-1049 | URL:http://www.debian.org/security/2006/dsa-1049 | FEDORA:FEDORA-2006-456 | URL:http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html | FEDORA:FEDORA-2006-461 | URL:http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html | GENTOO:GLSA-200604-17 | URL:http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml | MANDRIVA:MDKSA-2006:077 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:077 | REDHAT:RHSA-2006:0420 | URL:http://www.redhat.com/support/errata/RHSA-2006-0420.html | SGI:20060501-01-U | URL:ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc | SUSE:SUSE-SR:2006:010 | URL:http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html | BID:17682 | URL:http://www.securityfocus.com/bid/17682 | OVAL:oval:org.mitre.oval:def:10323 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10323 | VUPEN:ADV-2006-1501 | URL:http://www.vupen.com/english/advisories/2006/1501 | SECTRACK:1015985 | URL:http://securitytracker.com/id?1015985 | SECUNIA:19769 | URL:http://secunia.com/advisories/19769 | SECUNIA:19805 | URL:http://secunia.com/advisories/19805 | SECUNIA:19828 | URL:http://secunia.com/advisories/19828 | SECUNIA:19839 | URL:http://secunia.com/advisories/19839 | SECUNIA:19958 | URL:http://secunia.com/advisories/19958 | SECUNIA:19962 | URL:http://secunia.com/advisories/19962 | SECUNIA:20117 | URL:http://secunia.com/advisories/20117 | SECUNIA:20944 | URL:http://secunia.com/advisories/20944 | SECUNIA:20210 | URL:http://secunia.com/advisories/20210 | XF:ethereal-aim-dos(26019) | URL:http://xforce.iss.net/xforce/xfdb/26019 | XF:ethereal-general-dissector-dos(26018) | URL:http://xforce.iss.net/xforce/xfdb/26018 | XF:ethereal-h245-dos(26011) | URL:http://xforce.iss.net/xforce/xfdb/26011 | XF:ethereal-h248-dissector-dos(26007) | URL:http://xforce.iss.net/xforce/xfdb/26007 | XF:ethereal-h248-dos(26031) | URL:http://xforce.iss.net/xforce/xfdb/26031 | XF:ethereal-srvloc-dos(26010) | URL:http://xforce.iss.net/xforce/xfdb/26010 | XF:ethereal-statistics-counter-dos(26015) | URL:http://xforce.iss.net/xforce/xfdb/26015 | XF:ethereal-x509if-dissector-dos(26009) | URL:http://xforce.iss.net/xforce/xfdb/26009",Assigned (20060420),"None (candidate not yet proposed)",
44| [CVE-2006-2006,Candidate,"Multiple directory traversal vulnerabilities in IZArc Archiver 3.5 beta 3 allow remote attackers to write arbitrary files via a ..\ (dot dot backslash) in a (1) .rar, (2) .tar, (3) .zip, (4) .jar, or (5) .gz archive. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:17664 | URL:http://www.securityfocus.com/bid/17664 | VUPEN:ADV-2006-1488 | URL:http://www.vupen.com/english/advisories/2006/1488 | OSVDB:24895 | URL:http://www.osvdb.org/24895 | SECUNIA:19791 | URL:http://secunia.com/advisories/19791 | XF:izarc-extract-directory-traversal(26039) | URL:http://xforce.iss.net/xforce/xfdb/26039",Assigned (20060425),"None (candidate not yet proposed)",
45| [CVE-2006-2296,Candidate,"SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this information is unknown] the details are obtained from third party information.","MISC:http://downloads.securityfocus.com/vulnerabilities/exploits/edirectorypro-sql-inj.txt | BID:17912 | URL:http://www.securityfocus.com/bid/17912 | VUPEN:ADV-2006-1739 | URL:http://www.vupen.com/english/advisories/2006/1739 | OSVDB:25334 | URL:http://www.osvdb.org/25334 | SECUNIA:20017 | URL:http://secunia.com/advisories/20017 | XF:edirectorypro-search-sql-injection(26319) | URL:http://xforce.iss.net/xforce/xfdb/26319",Assigned (20060509),"None (candidate not yet proposed)",
46| [CVE-2006-2325,Candidate,"Cross-site scripting (XSS) vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to inject arbitrary web script or HTML via the read parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. Also, this issue might be resultant from directory traversal.","BID:17889 | URL:http://www.securityfocus.com/bid/17889 | VUPEN:ADV-2006-1704 | URL:http://www.vupen.com/english/advisories/2006/1704 | OSVDB:25452 | URL:http://www.osvdb.org/25452 | SECUNIA:20005 | URL:http://secunia.com/advisories/20005 | XF:oups-index-xss(26342) | URL:http://xforce.iss.net/xforce/xfdb/26342",Assigned (20060511),"None (candidate not yet proposed)",
47| [CVE-2006-2326,Candidate,"Directory traversal vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to read arbitrary files via directory traversal sequences in the read parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:17889 | URL:http://www.securityfocus.com/bid/17889 | VUPEN:ADV-2006-1704 | URL:http://www.vupen.com/english/advisories/2006/1704 | OSVDB:25451 | URL:http://www.osvdb.org/25451 | SECUNIA:20005 | URL:http://secunia.com/advisories/20005 | XF:oups-index-directory-traversal(26341) | URL:http://xforce.iss.net/xforce/xfdb/26341",Assigned (20060511),"None (candidate not yet proposed)",
48| [CVE-2006-2329,Candidate,"AngelineCMS 0.6.5 and earlier allow remote attackers to obtain sensitive information via a direct request for (1) adodb-access.inc.php, (2) adodb-ado.inc.php, (3) adodb-ado_access.inc, (4) adodb-ado_mssql.inc.php, (5) adodb-borland_ibase, (6) adodb-csv.inc.php, (7) adodb-db2.inc.php, (8) adodb-fbsql.inc.php, (9) adodb-firebird.inc.php, (10) adodb-ibase.inc.php, (11) adodb-informix.inc.php, (12) adodb-informix72.inc, (13) adodb-mssql.inc.php, (14) adodb-mssqlpo.inc.php, (15) adodb-mysql.inc.php, (16) adodb-mysqlt.inc.php, (17) adodb-oci8.inc.php, (18) adodb-oci805.inc.php, (19) adodb-oci8po.inc.php, and (20) adodb-odbc.inc.php, which reveal the path in various error messages] and via a direct request for the (21) lib/system/ directory and (22) possibly other lib/ directories, which provide a directory listing and ""architecture view.""","BUGTRAQ:20060507 AngelineCMS Multiple Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/433241/100/0/threaded | MISC:http://www.subjectzero.net/research/ang_CMS.htm | SREASON:883 | URL:http://securityreason.com/securityalert/883 | XF:angelinecms-adodbmssqlinc-path-disclosure(26383) | URL:http://xforce.iss.net/xforce/xfdb/26383",Assigned (20060511),"None (candidate not yet proposed)",
49| [CVE-2006-2553,Candidate,"Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl 1.0 allows remote attackers to inject arbitrary HTML or web script via the dcid parameter to dc.php. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. This issue appears to be independent from a different issue that involves the same vector.","BUGTRAQ:20060519 Jemscripts Download Control v1.0 | URL:http://www.securityfocus.com/archive/1/archive/1/434533/100/0/threaded | VIM:20060523 Jemscripts DownloadControl 1.0 - at least 2 separate issues | URL:http://www.attrition.org/pipermail/vim/2006-May/000783.html | VUPEN:ADV-2006-1928 | URL:http://www.vupen.com/english/advisories/2006/1928 | OSVDB:25715 | URL:http://www.osvdb.org/25715 | SECUNIA:20212 | URL:http://secunia.com/advisories/20212 | SREASON:943 | URL:http://securityreason.com/securityalert/943 | XF:downloadcontrol-dc-xss(26624) | URL:http://xforce.iss.net/xforce/xfdb/26624",Assigned (20060523),"None (candidate not yet proposed)",
50| [CVE-2006-2641,Candidate,"** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) vulnerability in John Frank Asset Manager (AssetMan) 2.4a and earlier allows remote attackers to inject arbitrary web script or HTML via ""any of its input."" NOTE: the original disclosure is based on vague researcher claims without vendor acknowledgement] therefore this identifier cannot be linked with any future identifier that identifies more specific vectors. Perhaps this should not be included in CVE.","BUGTRAQ:20060523 Assetman <= 2.4a XSS | URL:http://www.securityfocus.com/archive/1/archive/1/435139/100/0/threaded | BID:18131 | URL:http://www.securityfocus.com/bid/18131 | VUPEN:ADV-2006-2023 | URL:http://www.vupen.com/english/advisories/2006/2023 | SECUNIA:20285 | URL:http://secunia.com/advisories/20285 | SREASON:979 | URL:http://securityreason.com/securityalert/979 | XF:assetman-multiple-xss(26702) | URL:http://xforce.iss.net/xforce/xfdb/26702",Assigned (20060530),"None (candidate not yet proposed)",
51| [CVE-2006-2642,Candidate,"** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) vulnerability in Marco M. F. De Santis Php-residence 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via ""any of its input."" NOTE: the original disclosure is based on vague researcher claims without vendor acknowledgement] therefore this identifier cannot be linked with any future identifier that identifies more specific vectors. Perhaps this should not be included in CVE.","BUGTRAQ:20060523 PHPResidence <= 0.6 XSS | URL:http://www.securityfocus.com/archive/1/archive/1/435131/100/0/threaded | BID:18133 | URL:http://www.securityfocus.com/bid/18133 | VUPEN:ADV-2006-2025 | URL:http://www.vupen.com/english/advisories/2006/2025 | SECUNIA:20311 | URL:http://secunia.com/advisories/20311 | SREASON:978 | URL:http://securityreason.com/securityalert/978 | XF:phpresidence-multiple-xss(26701) | URL:http://xforce.iss.net/xforce/xfdb/26701",Assigned (20060530),"None (candidate not yet proposed)",
52| [CVE-2006-2731,Candidate,"Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) e_mesaj_yas.asp, (b) edi_haber.asp, and (c) haber_devam.asp] (2) hid parameter in (d) yazdir.asp and (e) yorum.asp, and the (3) e parameter in (f) arsiv.asp. NOTE: with administrator credentials, additional vectors exist including (4) yid parameter to (g) admin/y_admin.asp, (5) bid parameter to (h) admin/reklam_detay.asp, hid parameter to (i) admin/detay_yorum.asp and (j) admin/haber_sil.asp, (6) kid parameter to (k) admin/kategori_d.asp, (7) tur parameter to (l) admin/haber_ekle.asp, (8) s parameter to (m) admin/e_mesaj_yaz.asp, and id parameter to (n) admin/admin_sil.asp.","BUGTRAQ:20060528 Advisory: Enigma Haber <= 4.3 Multiple Remote SQL InjectionVulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/435282/100/0/threaded | MISC:http://www.nukedx.com/?getxpl=34 | MISC:http://www.nukedx.com/?viewdoc=34 | BID:18148 | URL:http://www.securityfocus.com/bid/18148 | VUPEN:ADV-2006-2032 | URL:http://www.vupen.com/english/advisories/2006/2032 | OSVDB:26106 | URL:http://www.osvdb.org/26106 | OSVDB:26107 | URL:http://www.osvdb.org/26107 | OSVDB:26111 | URL:http://www.osvdb.org/26111 | OSVDB:26112 | URL:http://www.osvdb.org/26112 | OSVDB:26113 | URL:http://www.osvdb.org/26113 | OSVDB:26114 | URL:http://www.osvdb.org/26114 | OSVDB:26115 | URL:http://www.osvdb.org/26115 | OSVDB:26116 | URL:http://www.osvdb.org/26116 | OSVDB:26117 | URL:http://www.osvdb.org/26117 | OSVDB:26118 | URL:http://www.osvdb.org/26118 | OSVDB:26119 | URL:http://www.osvdb.org/26119 | OSVDB:26108 | URL:http://www.osvdb.org/26108 | OSVDB:26109 | URL:http://www.osvdb.org/26109 | OSVDB:26110 | URL:http://www.osvdb.org/26110 | SECTRACK:1016171 | URL:http://securitytracker.com/id?1016171 | SECUNIA:20357 | URL:http://secunia.com/advisories/20357 | SREASON:1003 | URL:http://securityreason.com/securityalert/1003 | XF:enigmahaber-multiple-sql-injection(26837) | URL:http://xforce.iss.net/xforce/xfdb/26837",Assigned (20060601),"None (candidate not yet proposed)",
53| [CVE-2006-2772,Candidate,"Cross-site scripting (XSS) vulnerability in add.asp in Hogstorps hogstorp guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) headline parameters. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:18203 | URL:http://www.securityfocus.com/bid/18203 | VUPEN:ADV-2006-2082 | URL:http://www.vupen.com/english/advisories/2006/2082 | SECUNIA:20402 | URL:http://secunia.com/advisories/20402 | XF:hogstorp-guestbook-add-xss(26980) | URL:http://xforce.iss.net/xforce/xfdb/26980",Assigned (20060601),"None (candidate not yet proposed)",
54| [CVE-2006-2773,Candidate,"admin/redigera/redigera2.asp in Hogstorps hogstorp Guestbook 2.0 does not verify user credentials, which allows remote attackers to edit arbitrary posts via unspecified vectors. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","VUPEN:ADV-2006-2082 | URL:http://www.vupen.com/english/advisories/2006/2082 | SECUNIA:20402 | URL:http://secunia.com/advisories/20402 | XF:hogstorp-guestbook-redigera2-security-bypass(26979) | URL:http://xforce.iss.net/xforce/xfdb/26979",Assigned (20060601),"None (candidate not yet proposed)",
55| [CVE-2006-2958,Candidate,"Directory traversal vulnerability in FilZip 3.05 allows remote attackers to write arbitrary files via a .. (dot dot) in a (1) .rar, (2) .tar, (3) .jar, or (4) .gz file. NOTE: the provenance of this information is unknown] the details are obtained from third party information.","BID:18375 | URL:http://www.securityfocus.com/bid/18375 | VUPEN:ADV-2006-2255 | URL:http://www.vupen.com/english/advisories/2006/2255 | SECUNIA:20543 | URL:http://secunia.com/advisories/20543 | XF:filzip-archive-directory-traversal(27027) | URL:http://xforce.iss.net/xforce/xfdb/27027",Assigned (20060612),"None (candidate not yet proposed)",
56| [CVE-2006-3210,Candidate,"Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or "".."" sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and (d) admin_util.php] and the (2) dir_abs_admin_src parameter in admin_album.php and admin_image.php. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) attacks.","BUGTRAQ:20060620 [MajorSecurity #18] Ralf Image Gallery <=0.7.4 - Multiple XSS, Remote File Include and directory traversal vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/437818/100/0/threaded | BUGTRAQ:20060627 Re: [MajorSecurity #18] Ralf Image Gallery <=0.7.4 - Multiple XSS, Remote File Include and directory traversal vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/438645/100/100/threaded | MISC:http://www.majorsecurity.de/advisory/major_rls18.txt | CONFIRM:http://rig.powerpulsar.com/#news | BID:18548 | URL:http://www.securityfocus.com/bid/18548 | VUPEN:ADV-2006-2477 | URL:http://www.vupen.com/english/advisories/2006/2477 | OSVDB:26753 | URL:http://www.osvdb.org/26753 | OSVDB:26754 | URL:http://www.osvdb.org/26754 | OSVDB:26755 | URL:http://www.osvdb.org/26755 | OSVDB:26756 | URL:http://www.osvdb.org/26756 | SECUNIA:20771 | URL:http://secunia.com/advisories/20771 | SREASON:1136 | URL:http://securityreason.com/securityalert/1136 | XF:rig-dirabssrc-dirabsadminsrc-file-include(27259) | URL:http://xforce.iss.net/xforce/xfdb/27259 | XF:rig-dirabssrc-dirabsadminsrc-xss(27257) | URL:http://xforce.iss.net/xforce/xfdb/27257 | XF:rig-dirabssrc-directory-traversal(27256) | URL:http://xforce.iss.net/xforce/xfdb/27256",Assigned (20060623),"None (candidate not yet proposed)",
57| [CVE-2006-3326,Candidate,"Directory traversal vulnerability in QuickZip 3.06.3 allows remote user-assisted attackers to overwrite arbitrary files or directories via .. (dot dot) sequences in filenames within (1) TAR,(2) GZ, and (3) JAR archives. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:18722 | URL:http://www.securityfocus.com/bid/18722 | VUPEN:ADV-2006-2599 | URL:http://www.vupen.com/english/advisories/2006/2599 | OSVDB:26908 | URL:http://www.osvdb.org/26908 | SECUNIA:20864 | URL:http://secunia.com/advisories/20864 | XF:quickzip-extract-directory-traversal(27474) | URL:http://xforce.iss.net/xforce/xfdb/27474",Assigned (20060630),"None (candidate not yet proposed)",
58| [CVE-2006-3533,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) fg, (2) line1, (3) line2, (4) bg, (5) c1, (6) c2, (7) c3, and (8) c4 parameters in (a) includes/blogroll.php] (9) name and (10) js_name parameters in (b) includes/editor/edit_menu.php
59| [CVE-2006-3806,Candidate,"Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects] and (2) unspecified ""string function arguments.""","BUGTRAQ:20060727 rPSA-2006-0137-1 firefox | URL:http://www.securityfocus.com/archive/1/archive/1/441333/100/0/threaded | CONFIRM:http://www.mozilla.org/security/announce/2006/mfsa2006-50.html | CONFIRM:https://issues.rpath.com/browse/RPL-536 | CONFIRM:https://issues.rpath.com/browse/RPL-537 | DEBIAN:DSA-1159 | URL:http://www.debian.org/security/2006/dsa-1159 | DEBIAN:DSA-1160 | URL:http://www.debian.org/security/2006/dsa-1160 | DEBIAN:DSA-1161 | URL:http://www.debian.org/security/2006/dsa-1161 | GENTOO:GLSA-200608-02 | URL:http://security.gentoo.org/glsa/glsa-200608-02.xml | GENTOO:GLSA-200608-04 | URL:http://security.gentoo.org/glsa/glsa-200608-04.xml | GENTOO:GLSA-200608-03 | URL:http://www.gentoo.org/security/en/glsa/glsa-200608-03.xml | HP:HPSBUX02153 | URL:http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded | HP:SSRT061181 | URL:http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded | HP:HPSBUX02156 | URL:http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded | HP:SSRT061236 | URL:http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded | MANDRIVA:MDKSA-2006:143 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:143 | MANDRIVA:MDKSA-2006:145 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:145 | MANDRIVA:MDKSA-2006:146 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:146 | REDHAT:RHSA-2006:0608 | URL:http://www.redhat.com/support/errata/RHSA-2006-0608.html | REDHAT:RHSA-2006:0610 | URL:http://www.redhat.com/support/errata/RHSA-2006-0610.html | REDHAT:RHSA-2006:0611 | URL:http://www.redhat.com/support/errata/RHSA-2006-0611.html | REDHAT:RHSA-2006:0609 | URL:http://rhn.redhat.com/errata/RHSA-2006-0609.html | REDHAT:RHSA-2006:0594 | URL:http://www.redhat.com/support/errata/RHSA-2006-0594.html | SGI:20060703-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc | SUNALERT:102763 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102763-1 | SUSE:SUSE-SA:2006:048 | URL:http://www.novell.com/linux/security/advisories/2006_48_seamonkey.html | UBUNTU:USN-327-1 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-327-1 | UBUNTU:USN-329-1 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-329-1 | UBUNTU:USN-350-1 | URL:http://www.ubuntu.com/usn/usn-350-1 | UBUNTU:USN-354-1 | URL:http://www.ubuntu.com/usn/usn-354-1 | UBUNTU:USN-361-1 | URL:http://www.ubuntu.com/usn/usn-361-1 | CERT:TA06-208A | URL:http://www.us-cert.gov/cas/techalerts/TA06-208A.html | CERT-VN:VU#655892 | URL:http://www.kb.cert.org/vuls/id/655892 | BID:19181 | URL:http://www.securityfocus.com/bid/19181 | OVAL:oval:org.mitre.oval:def:11232 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11232 | VUPEN:ADV-2006-2998 | URL:http://www.vupen.com/english/advisories/2006/2998 | VUPEN:ADV-2007-0058 | URL:http://www.vupen.com/english/advisories/2007/0058 | VUPEN:ADV-2006-3748 | URL:http://www.vupen.com/english/advisories/2006/3748 | VUPEN:ADV-2006-3749 | URL:http://www.vupen.com/english/advisories/2006/3749 | VUPEN:ADV-2008-0083 | URL:http://www.vupen.com/english/advisories/2008/0083 | SECTRACK:1016586 | URL:http://securitytracker.com/id?1016586 | SECTRACK:1016587 | URL:http://securitytracker.com/id?1016587 | SECTRACK:1016588 | URL:http://securitytracker.com/id?1016588 | SECUNIA:19873 | URL:http://secunia.com/advisories/19873 | SECUNIA:21216 | URL:http://secunia.com/advisories/21216 | SECUNIA:21228 | URL:http://secunia.com/advisories/21228 | SECUNIA:21229 | URL:http://secunia.com/advisories/21229 | SECUNIA:21246 | URL:http://secunia.com/advisories/21246 | SECUNIA:21243 | URL:http://secunia.com/advisories/21243 | SECUNIA:21269 | URL:http://secunia.com/advisories/21269 | SECUNIA:21270 | URL:http://secunia.com/advisories/21270 | SECUNIA:21275 | URL:http://secunia.com/advisories/21275 | SECUNIA:21336 | URL:http://secunia.com/advisories/21336 | SECUNIA:21358 | URL:http://secunia.com/advisories/21358 | SECUNIA:21361 | URL:http://secunia.com/advisories/21361 | SECUNIA:21250 | URL:http://secunia.com/advisories/21250 | SECUNIA:21262 | URL:http://secunia.com/advisories/21262 | SECUNIA:21343 | URL:http://secunia.com/advisories/21343 | SECUNIA:21529 | URL:http://secunia.com/advisories/21529 | SECUNIA:21532 | URL:http://secunia.com/advisories/21532 | SECUNIA:21607 | URL:http://secunia.com/advisories/21607 | SECUNIA:21631 | URL:http://secunia.com/advisories/21631 | SECUNIA:21654 | URL:http://secunia.com/advisories/21654 | SECUNIA:21634 | URL:http://secunia.com/advisories/21634 | SECUNIA:21675 | URL:http://secunia.com/advisories/21675 | SECUNIA:22055 | URL:http://secunia.com/advisories/22055 | SECUNIA:22210 | URL:http://secunia.com/advisories/22210 | SECUNIA:22342 | URL:http://secunia.com/advisories/22342 | SECUNIA:22065 | URL:http://secunia.com/advisories/22065 | SECUNIA:22066 | URL:http://secunia.com/advisories/22066 | XF:mozilla-javascript-engine-overflow(27987) | URL:http://xforce.iss.net/xforce/xfdb/27987",Assigned (20060724),"None (candidate not yet proposed)",
60| [CVE-2006-3826,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in register.php] and allow remote authenticated administrators to inject arbitrary web script or HTML via the (4) cat_list and (5) key parameters in a certain portion of the admin interface.","BUGTRAQ:20060717 boastMachine <= 3.1 SQL Injection Exploit | URL:http://www.securityfocus.com/archive/1/archive/1/440306/100/0/threaded | MISC:http://www.acid-root.new.fr/advisories/boastmachine.txt | VUPEN:ADV-2006-2849 | URL:http://www.vupen.com/english/advisories/2006/2849 | SECTRACK:1016515 | URL:http://securitytracker.com/id?1016515 | SECUNIA:21066 | URL:http://secunia.com/advisories/21066 | SREASON:1252 | URL:http://securityreason.com/securityalert/1252 | XF:boastmachine-register-xss(27771) | URL:http://xforce.iss.net/xforce/xfdb/27771",Assigned (20060724),"None (candidate not yet proposed)",
61| [CVE-2006-3942,Candidate,"The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an ""SMB PIPE,"" aka the ""Mailslot DOS"" vulnerability. NOTE: the name ""Mailslot DOS"" was derived from incomplete initial research] the vulnerability is not associated with a mailslot.","ISS:20060728 Vulnerability in Server Driver could result in Denial of Service | URL:http://xforce.iss.net/xforce/alerts/id/231 | BUGTRAQ:20060814 CORE-2006-0714: Microsoft SRV.SYS SMB_COM_TRANSACTION Denial of Service | URL:http://www.securityfocus.com/archive/1/archive/1/443287/100/200/threaded | MISC:http://blogs.technet.com/msrc/archive/2006/07/28/443837.aspx | MILW0RM:2057 | URL:http://milw0rm.com/exploits/2057 | MISC:http://www.coresecurity.com/common/showdoc.php?idx=562&idxseccion=10 | HP:HPSBST02161 | URL:http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded | HP:SSRT061264 | URL:http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded | MS:MS06-063 | URL:http://www.microsoft.com/technet/security/Bulletin/MS06-063.mspx | BID:19215 | URL:http://www.securityfocus.com/bid/19215 | VUPEN:ADV-2006-3037 | URL:http://www.vupen.com/english/advisories/2006/3037 | OSVDB:27644 | URL:http://www.osvdb.org/27644 | OVAL:oval:org.mitre.oval:def:428 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:428 | SECTRACK:1016606 | URL:http://securitytracker.com/id?1016606 | SECTRACK:1017035 | URL:http://securitytracker.com/id?1017035 | SECUNIA:21276 | URL:http://secunia.com/advisories/21276 | XF:smb-malformed-pipe(27999) | URL:http://xforce.iss.net/xforce/xfdb/27999",Assigned (20060731),"None (candidate not yet proposed)",
62| [CVE-2006-4116,Candidate,"Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction] and (2) an LHZ archive with an invalid CRC checksum, when constructing an error message.","BUGTRAQ:20060807 [vuln.sg] Lhaz LHA Long Filename Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/442445/100/0/threaded | MISC:http://vuln.sg/lhaz131-en.html | CONFIRM:http://www.chitora.jp/lhaz.html | BID:19377 | URL:http://www.securityfocus.com/bid/19377 | VUPEN:ADV-2006-3173 | URL:http://www.vupen.com/english/advisories/2006/3173 | SECUNIA:21348 | URL:http://secunia.com/advisories/21348 | SREASON:1378 | URL:http://securityreason.com/securityalert/1378 | XF:lhaz-error-bo(28283) | URL:http://xforce.iss.net/xforce/xfdb/28283 | XF:lhaz-long-filename-bo(28282) | URL:http://xforce.iss.net/xforce/xfdb/28282",Assigned (20060814),"None (candidate not yet proposed)",
63| [CVE-2006-4468,Candidate,"Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions] (4) the lack of inclusion of globals.php in administrator/index.php
64| [CVE-2006-4621,Candidate,"PHP remote file inclusion vulnerability in settings.php in Pheap 1.2, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. NOTE: the provenance of this information is unknown] the details are obtained from third party information. The lib/config.php vector is already covered by CVE-2006-4531.","VUPEN:ADV-2006-3426 | URL:http://www.vupen.com/english/advisories/2006/3426 | SECUNIA:21678 | URL:http://secunia.com/advisories/21678",Assigned (20060906),"None (candidate not yet proposed)",
65| [CVE-2006-4889,Candidate,"Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3) includes/functions.admin.php, (4) includes/admin.inc.php, (5) help.php, (6) smile.php, (7) entry.php] (8) adminhelp0.php, (9) adminhelp1.php, (10) adminhelp2.php, and (11) adminhelp3.php in (a) help/en and (b) help/de directories
66| [CVE-2006-5113,Candidate,"Directory traversal vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to include and execute local files via a .. (dot dot) in the lan parameter to includes.php. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","MISC:http://packetstormsecurity.org/0610-exploits/Exporia-0.3.0.txt | VUPEN:ADV-2006-3799 | URL:http://www.vupen.com/english/advisories/2006/3799 | OSVDB:29218 | URL:http://www.osvdb.org/29218 | SECUNIA:22146 | URL:http://secunia.com/advisories/22146 | XF:exporia-includes-file-include(29326) | URL:http://xforce.iss.net/xforce/xfdb/29326",Assigned (20061002),"None (candidate not yet proposed)",
67| [CVE-2006-5143,Candidate,"Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01] BrightStor ARCserve Backup for Windows r11
68| [CVE-2006-5220,Candidate,"Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the webyep_sIncludePath in (1) files in the programm/lib/ directory including (a) WYApplication.php, (b) WYDocument.php, (c) WYEditor.php, (d) WYElement.php, (e) WYFile.php, (f) WYHTMLTag.php, (g) WYImage.php, (h) WYLanguage.php, (i) WYLink.php, (j) WYPath.php, (k) WYPopupWindowLink.php, (l) WYSelectMenu.php, and (m) WYTextArea.php] (2) files in the programm/elements/ directory including (n) WYGalleryElement.php, (o) WYGuestbookElement.php, (p) WYImageElement.php, (q) WYLogonButtonElement.php, (r) WYLongTextElement.php, (s) WYLoopElement.php, (t) WYMenuElement.php, and (u) WYShortTextElement.php
69| [CVE-2006-5406,Candidate,"Passgo Defender 5.2 creates the application directory with insecure permissions (Everyone/Full Control), which allows local users to read and modify sensitive files. NOTE: the provenance of this information is unknown] the details are obtained from third party information.","BID:20600 | URL:http://www.securityfocus.com/bid/20600 | VUPEN:ADV-2006-4091 | URL:http://www.vupen.com/english/advisories/2006/4091 | OSVDB:29789 | URL:http://www.osvdb.org/29789 | SECUNIA:22271 | URL:http://secunia.com/advisories/22271 | XF:defender-directory-insecure-permission(29657) | URL:http://xforce.iss.net/xforce/xfdb/29657",Assigned (20061018),"None (candidate not yet proposed)",
70| [CVE-2006-5451,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) file, and (3) users array variables in (a) admin.php, which are not properly handled when the administrator views the Activity Log] and the (4) torrent parameter, as used by the displayName variable, in (b) startpop.php, different vectors than CVE-2006-5227.","BUGTRAQ:20061013 TorrentFlux ?startpop.php? ?torrent? Script Insertion | URL:http://www.securityfocus.com/archive/1/archive/1/448619/100/100/threaded | BUGTRAQ:20061017 TorrentFlux ?action? Script Insertion | URL:http://www.securityfocus.com/archive/1/archive/1/448947/100/0/threaded | BUGTRAQ:20061017 TorrentFlux ?file? Script Insertion | URL:http://www.securityfocus.com/archive/1/archive/1/448948/100/0/threaded | BUGTRAQ:20061017 TorrentFlux ?user_id? Script Insertion | URL:http://www.securityfocus.com/archive/1/archive/1/448952/100/0/threaded | MISC:http://www.stevenroddis.com.au/2006/10/13/torrentflux-startpopphp-torrent-script-insertion/ | MISC:http://www.stevenroddis.com.au/2006/10/17/torrentflux-action-script-insertion/ | MISC:http://www.stevenroddis.com.au/2006/10/17/torrentflux-file-script-insertion/ | MISC:http://www.stevenroddis.com.au/2006/10/17/torrentflux-user_id-script-insertion/ | BID:20534 | URL:http://www.securityfocus.com/bid/20534 | VUPEN:ADV-2006-4043 | URL:http://www.vupen.com/english/advisories/2006/4043 | SECUNIA:22384 | URL:http://secunia.com/advisories/22384 | XF:torrentflux-startpop-xss(29592) | URL:http://xforce.iss.net/xforce/xfdb/29592",Assigned (20061023),"None (candidate not yet proposed)",
71| [CVE-2006-5478,Candidate,"Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function] or vectors related to a username containing a . (dot) character in the (2) SMTP, (3) POP, (4) IMAP, (5) HTTP, or (6) Networked Messaging Application Protocol (NMAP) Netmail services.","BUGTRAQ:20061026 ZDI-06-035: Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/449899/100/0/threaded | BUGTRAQ:20061028 Re: [Full-disclosure] ZDI-06-035: Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/450017/100/0/threaded | BUGTRAQ:20061103 ZDI-06-036: Novell Netmail User Authentication Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/450520/100/100/threaded | FULLDISC:20061028 ZDI-06-035: Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability | URL:http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050382.html | FULLDISC:20061028 ZDI-06-035: Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability | URL:http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050388.html | MISC:http://www.mnin.org/advisories/2006_novell_httpstk.pdf | MISC:http://www.zerodayinitiative.com/advisories/ZDI-06-035.html | MISC:http://www.zerodayinitiative.com/advisories/ZDI-06-036.html | CONFIRM:http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974600.htm | CONFIRM:http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=3723994&sliceId=SAL_Public&dialogID=16776123&stateId=1%200%202648401 | CONFIRM:https://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html | BID:20655 | URL:http://www.securityfocus.com/bid/20655 | BID:20853 | URL:http://www.securityfocus.com/bid/20853 | VUPEN:ADV-2006-4141 | URL:http://www.vupen.com/english/advisories/2006/4141 | SECTRACK:1017125 | URL:http://securitytracker.com/id?1017125 | SECTRACK:1017141 | URL:http://securitytracker.com/id?1017141 | SECUNIA:22519 | URL:http://secunia.com/advisories/22519",Assigned (20061024),"None (candidate not yet proposed)",
72| [CVE-2006-5495,Candidate,"Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_red2 parameter to (a) _msdazu_pdata/redaktion/artikel/up/index.php] (b) addtort.php, (c) colorpik2.php, (d) colorpik3.php, (e) extras_menu.php, (f) farbpalette.php, (g) lese_inc.php, and (h) newfile.php in _msdazu_share/richtext/
73| [CVE-2006-5506,Candidate,"Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code via the path parameter in (1) inc/prepend.inc.php, (2) inc/lib/boxes.lib.php, (3) inc/lib/tools.lib.php, (4) tools/trackback/index.php, and (5) tools/utf8conversion/index.php in admin/] and (6) prepend.inc.php, (7) lib/boxes.lib.php, and (8) lib/history.lib.php in inc/.","MILW0RM:2624 | URL:http://milw0rm.com/exploits/2624 | CONFIRM:http://wiclear.free.fr/ | CONFIRM:http://wiclear.free.fr/?Download | VUPEN:ADV-2006-4166 | URL:http://www.vupen.com/english/advisories/2006/4166 | OSVDB:29942 | URL:http://www.osvdb.org/29942 | OSVDB:29943 | URL:http://www.osvdb.org/29943 | OSVDB:29944 | URL:http://www.osvdb.org/29944 | OSVDB:29945 | URL:http://www.osvdb.org/29945 | OSVDB:29946 | URL:http://www.osvdb.org/29946 | OSVDB:29947 | URL:http://www.osvdb.org/29947 | OSVDB:29948 | URL:http://www.osvdb.org/29948 | OSVDB:29949 | URL:http://www.osvdb.org/29949 | SECUNIA:22547 | URL:http://secunia.com/advisories/22547 | XF:wiclear-path-file-include(29720) | URL:http://xforce.iss.net/xforce/xfdb/29720",Assigned (20061025),"None (candidate not yet proposed)",
74| [CVE-2006-5632,Candidate,"Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-5631. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","VIM:20061031 Ig-shop change_pass.php XSS - 2 vectors | URL:http://www.attrition.org/pipermail/vim/2006-October/001099.html | BID:20768 | URL:http://www.securityfocus.com/bid/20768 | SECTRACK:1017130 | URL:http://securitytracker.com/id?1017130 | SECUNIA:22701 | URL:http://secunia.com/advisories/22701",Assigned (20061031),"None (candidate not yet proposed)",
75| [CVE-2006-5763,Candidate,"Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter to (1) login.php, (2) register.php, or (3) send.php. NOTE: the original provenance of this information is unknown] the details are obtained solely from third party information. NOTE: this issue was later reported for the ""File Upload System"" which is a component of Free File Hosting. Vector 1 also affects Free Image Hosting 2.0, which contains the same code.","BUGTRAQ:20070324 File Upload System V1.0 (AD_BODY_TEMP) multiple file include | URL:http://www.securityfocus.com/archive/1/archive/1/463707/100/0/threaded | MILW0RM:3568 | URL:http://www.milw0rm.com/exploits/3568 | VIM:20070327 ""File Upload"" seems to be ""Free File Hosting"" | URL:http://www.attrition.org/pipermail/vim/2007-March/001473.html | BID:23118 | URL:http://www.securityfocus.com/bid/23118 | OSVDB:30144 | URL:http://www.osvdb.org/30144 | OSVDB:30145 | URL:http://www.osvdb.org/30145 | OSVDB:30146 | URL:http://www.osvdb.org/30146 | SECUNIA:22594 | URL:http://secunia.com/advisories/22594 | XF:freefile-forgot-file-include(29874) | URL:http://xforce.iss.net/xforce/xfdb/29874 | XF:freeimagehosting-adbodytemp-file-include(33196) | URL:http://xforce.iss.net/xforce/xfdb/33196",Assigned (20061106),"None (candidate not yet proposed)",
76| [CVE-2006-5800,Candidate,"Cross-site scripting (XSS) vulnerability in default.asp in xenis.creator CMS allows remote attackers to inject arbitrary web script or HTML via the nav parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","XF:xeniscreatorcms-default-xss(30019) | URL:http://xforce.iss.net/xforce/xfdb/30019",Assigned (20061108),"None (candidate not yet proposed)",
77| [CVE-2006-5897,Candidate,"Multiple directory traversal vulnerabilities in PhpMyChat Plus 1.9 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the ChatPath parameter to (1) avatar.php, (2) colorhelp_popup.php, (3) color_popup.php, (4) index.php, (5) index1.php, (6) lib/connected_users.lib.php, (7) lib/index.lib.php, and (8) phpMyChat.php3] and the (9) L parameter to logs.php. NOTE: CVE analysis suggests that vector 1 might be incorrect.","BUGTRAQ:20061108 PhpMyChat Plus <= 1.9 Multiple Source Code Disclosure Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/450919/100/0/threaded | VUPEN:ADV-2006-4454 | URL:http://www.vupen.com/english/advisories/2006/4454 | SECUNIA:22782 | URL:http://secunia.com/advisories/22782 | SREASON:1854 | URL:http://securityreason.com/securityalert/1854 | XF:phpmychatplus-chatpath-source-disclosure(30122) | URL:http://xforce.iss.net/xforce/xfdb/30122",Assigned (20061115),"None (candidate not yet proposed)",
78| [CVE-2006-5947,Candidate,"Multiple directory traversal vulnerabilities in Conxint FTP Server 2.2.0603, and possibly earlier, allow remote attackers to read arbitrary files and list arbitrary directories via directory traversal sequences in (1) DIR (LIST or NLST) and (2) GET (RETR) commands. NOTE: the provenance of this information is unknown] details are obtained from third party sources.","BID:21081 | URL:http://www.securityfocus.com/bid/21081 | VUPEN:ADV-2006-4519 | URL:http://www.vupen.com/english/advisories/2006/4519 | SECUNIA:22893 | URL:http://secunia.com/advisories/22893 | XF:conxintftp-directory-traversal(30295) | URL:http://xforce.iss.net/xforce/xfdb/30295",Assigned (20061116),"None (candidate not yet proposed)",
79| [CVE-2006-5970,Candidate,"Verity Ultraseek before 5.7 allows remote attackers to obtain sensitive information via direct requests with (1) a null (""%00"") terminated url parameter to help/urlstatusgo.html] or missing parameters to (2) help/header.html, (3) help/footer.html, (4) spell.html, (5) coreforma.html, (6) daterange.html, (7) hits.html, (8) hitsnavbottom.html, (9) indexform.html, (10) indexforma.html, (11) languages.html, (12) nohits.html, (13) onehit1.html, (14) onehit2.html, (15) query.html, (16) queryform0.html, (17) queryform0a.html, (18) queryform1.html, (19) queryform1a.html, (20) queryform2.html, (21) queryform2a.html, (22) quicklinks.html, (23) relatedtopics.html, (24) signin.html, (25) subtopics.html, (26) thesaurus.html, (27) topics.html, (28) hitspagebar.html, (29) highlight/highlight.html, (30) highlight/highlight_one.html, and (31) highlight/topnav.html, which leaks the installation path in the resulting error message.","BUGTRAQ:20061115 ZDI-06-042: Verity Ultraseek Request Proxying Vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/451847/100/0/threaded | MISC:http://www.ultraseek.com/support/docs/RELNOTES.txt | MISC:http://www.zerodayinitiative.com/advisories/ZDI-06-042.html | OSVDB:30287 | URL:http://www.osvdb.org/30287 | OSVDB:30288 | URL:http://www.osvdb.org/30288 | SECTRACK:1017235 | URL:http://securitytracker.com/id?1017235 | SECUNIA:22892 | URL:http://secunia.com/advisories/22892 | XF:verity-ultraseek-scripts-info-disclosure(30314) | URL:http://xforce.iss.net/xforce/xfdb/30314",Assigned (20061117),"None (candidate not yet proposed)",
80| [CVE-2006-5984,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txtCompanyName, (2) txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4) setThemeColour parameter to (b) default.asp in the Reseller and Admin levels] or the (5) setThemeColour parameter to default.asp in the User level. NOTE: the txtDomainName parameter to domains.asp is covered by CVE-2006-1407, which suggests that this vector is fixed in 3.2.10 stable.","BUGTRAQ:20061114 Helm Cross-Site Scripting (XSS) | URL:http://www.securityfocus.com/archive/1/archive/1/451737/100/0/threaded | BUGTRAQ:20061116 Helm Cross Site Scripting | URL:http://www.securityfocus.com/archive/1/archive/1/451848/100/200/threaded | MISC:http://aria-security.net/advisory/helm.txt | VUPEN:ADV-2006-4557 | URL:http://www.vupen.com/english/advisories/2006/4557 | SECTRACK:1017240 | URL:http://securitytracker.com/id?1017240 | SECUNIA:22916 | URL:http://secunia.com/advisories/22916 | SREASON:1884 | URL:http://securityreason.com/securityalert/1884 | XF:helm-domainsusersdefaault-xss(30309) | URL:http://xforce.iss.net/xforce/xfdb/30309",Assigned (20061120),"None (candidate not yet proposed)",
81| [CVE-2006-6077,Candidate,"The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier] and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password.","BUGTRAQ:20061122 Big Flaw in Firefox 2: Password Manager Bug Exposes Passwords | URL:http://www.securityfocus.com/archive/1/archive/1/452382/100/0/threaded | BUGTRAQ:20061123 Password Flaw also in Firefox 1.5.08. Was: Big Flaw in Firefox 2: Password Manager Bug Exposes Passwords | URL:http://www.securityfocus.com/archive/1/archive/1/452431/100/0/threaded | BUGTRAQ:20061123 Re: Big Flaw in Firefox 2: Password Manager Bug Exposes Passwords | URL:http://www.securityfocus.com/archive/1/archive/1/452440/100/0/threaded | BUGTRAQ:20061123 Re: Password Flaw also in Firefox 1.5.08. Was: Big Flaw in Firefox 2: Password Manager Bug Exposes Passwords | URL:http://www.securityfocus.com/archive/1/archive/1/452463/100/0/threaded | BUGTRAQ:20061220 critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip | URL:http://www.securityfocus.com/archive/1/archive/1/454982/100/0/threaded | BUGTRAQ:20061221 Re: critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip | URL:http://www.securityfocus.com/archive/1/archive/1/455073/100/0/threaded | BUGTRAQ:20061222 Re[2]: critical Flaw in Firefox 2.0.0.1 allows to steal the user passwords with a videoclip | URL:http://www.securityfocus.com/archive/1/archive/1/455148/100/0/threaded | BUGTRAQ:20070226 rPSA-2007-0040-1 firefox | URL:http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded | BUGTRAQ:20070303 rPSA-2007-0040-3 firefox thunderbird | URL:http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded | MISC:http://www.info-svc.com/news/11-21-2006/ | MISC:http://www.info-svc.com/news/11-21-2006/rcsr1/ | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=360493 | CONFIRM:http://www.mozilla.org/security/announce/2007/mfsa2007-02.html | CONFIRM:https://issues.rpath.com/browse/RPL-1081 | CONFIRM:https://issues.rpath.com/browse/RPL-1103 | DEBIAN:DSA-1336 | URL:http://www.debian.org/security/2007/dsa-1336 | FEDORA:FEDORA-2007-281 | URL:http://fedoranews.org/cms/node/2713 | FEDORA:FEDORA-2007-293 | URL:http://fedoranews.org/cms/node/2728 | GENTOO:GLSA-200703-04 | URL:http://security.gentoo.org/glsa/glsa-200703-04.xml | GENTOO:GLSA-200703-08 | URL:http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml | HP:HPSBUX02153 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 | HP:SSRT061181 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 | MANDRIVA:MDKSA-2007:050 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:050 | REDHAT:RHSA-2007:0079 | URL:http://www.redhat.com/support/errata/RHSA-2007-0079.html | REDHAT:RHSA-2007:0077 | URL:http://rhn.redhat.com/errata/RHSA-2007-0077.html | REDHAT:RHSA-2007:0078 | URL:http://www.redhat.com/support/errata/RHSA-2007-0078.html | REDHAT:RHSA-2007:0097 | URL:http://www.redhat.com/support/errata/RHSA-2007-0097.html | REDHAT:RHSA-2007:0108 | URL:http://www.redhat.com/support/errata/RHSA-2007-0108.html | SGI:20070301-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc | SGI:20070202-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc | SLACKWARE:SSA:2007-066-05 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131 | SUSE:SUSE-SA:2007:019 | URL:http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html | SUSE:SUSE-SA:2007:022 | URL:http://www.novell.com/linux/security/advisories/2007_22_mozilla.html | UBUNTU:USN-428-1 | URL:http://www.ubuntu.com/usn/usn-428-1 | BID:21240 | URL:http://www.securityfocus.com/bid/21240 | BID:22694 | URL:http://www.securityfocus.com/bid/22694 | OVAL:oval:org.mitre.oval:def:10031 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10031 | VUPEN:ADV-2006-4662 | URL:http://www.vupen.com/english/advisories/2006/4662 | VUPEN:ADV-2007-0718 | URL:http://www.vupen.com/english/advisories/2007/0718 | SECTRACK:1017271 | URL:http://securitytracker.com/id?1017271 | SECUNIA:23046 | URL:http://secunia.com/advisories/23046 | SECUNIA:23108 | URL:http://secunia.com/advisories/23108 | SECUNIA:24238 | URL:http://secunia.com/advisories/24238 | SECUNIA:24287 | URL:http://secunia.com/advisories/24287 | SECUNIA:24290 | URL:http://secunia.com/advisories/24290 | SECUNIA:24205 | URL:http://secunia.com/advisories/24205 | SECUNIA:24328 | URL:http://secunia.com/advisories/24328 | SECUNIA:24333 | URL:http://secunia.com/advisories/24333 | SECUNIA:24343 | URL:http://secunia.com/advisories/24343 | SECUNIA:24320 | URL:http://secunia.com/advisories/24320 | SECUNIA:24293 | URL:http://secunia.com/advisories/24293 | SECUNIA:24393 | URL:http://secunia.com/advisories/24393 | SECUNIA:24395 | URL:http://secunia.com/advisories/24395 | SECUNIA:24384 | URL:http://secunia.com/advisories/24384 | SECUNIA:24437 | URL:http://secunia.com/advisories/24437 | SECUNIA:24650 | URL:http://secunia.com/advisories/24650 | SECUNIA:24457 | URL:http://secunia.com/advisories/24457 | SECUNIA:24342 | URL:http://secunia.com/advisories/24342 | SECUNIA:25588 | URL:http://secunia.com/advisories/25588 | XF:firefox-passwordmgr-information-disclosure(30470) | URL:http://xforce.iss.net/xforce/xfdb/30470",Assigned (20061124),"None (candidate not yet proposed)",
82| [CVE-2006-6185,Candidate,"Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to index.php.","BUGTRAQ:20061119 Wabbit PHP Gallery => 0.9 Remote Traversal Directory | URL:http://www.securityfocus.com/archive/1/archive/1/452170/100/100/threaded | VIM:20061130 Wabbit directory traversal - uncertain impact] enomphp uncertainty | URL:http://www.attrition.org/pipermail/vim/2006-November/001152.html | BID:21213 | URL:http://www.securityfocus.com/bid/21213 | VUPEN:ADV-2006-4640 | URL:http://www.vupen.com/english/advisories/2006/4640 | SECUNIA:22994 | URL:http://secunia.com/advisories/22994 | SREASON:1939 | URL:http://securityreason.com/securityalert/1939 | XF:wabbitphpgallery-index-directory-traversal(30429) | URL:http://xforce.iss.net/xforce/xfdb/30429",Assigned (20061130),"None (candidate not yet proposed)",
83| [CVE-2006-6186,Candidate,"Multiple directory traversal vulnerabilities in enomphp 4.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to (1) config.php, (2) ranklv_inside.php, (3) rankml_inside.php, and (4) admin/Restore/config.php.","BUGTRAQ:20061119 enomphp => 4.0 Remote Traversal Directory | URL:http://www.securityfocus.com/archive/1/archive/1/452123/100/100/threaded | VIM:20061130 Wabbit directory traversal - uncertain impact] enomphp uncertainty | URL:http://www.attrition.org/pipermail/vim/2006-November/001152.html | SREASON:1940 | URL:http://securityreason.com/securityalert/1940 | XF:enomphp-multiple-directory-traversal(30437) | URL:http://xforce.iss.net/xforce/xfdb/30437",Assigned (20061130),"None (candidate not yet proposed)",
84| [CVE-2006-6240,Candidate,"Directory traversal vulnerability in Sorin Chitu Telnet-FTP Server 1.0 allows remote authenticated users to list contents of arbitrary directories and download arbitrary files via a .. (dot dot) sequence in an FTP command argument, as demonstrated by RETR (GET) or STOR (PUT). NOTE: The provenance of this information is unknown] the details are obtained solely from third party information.","BID:21339 | URL:http://www.securityfocus.com/bid/21339 | VUPEN:ADV-2006-4765 | URL:http://www.vupen.com/english/advisories/2006/4765 | SECUNIA:22921 | URL:http://secunia.com/advisories/22921 | XF:sorinchitu-unspecified-directory-traversal(30582) | URL:http://xforce.iss.net/xforce/xfdb/30582",Assigned (20061203),"None (candidate not yet proposed)",
85| [CVE-2006-6242,Candidate,"Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .. (dot dot) sequence in the serendipity[charset] parameter in (1) include/lang.inc.php] or to plugins/ scripts (2) serendipity_event_bbcode/serendipity_event_bbcode.php, (3) serendipity_event_browsercompatibility/serendipity_event_browsercompatibility.php, (4) serendipity_event_contentrewrite/serendipity_event_contentrewrite.php, (5) serendipity_event_creativecommons/serendipity_event_creativecommons.php, (6) serendipity_event_emoticate/serendipity_event_emoticate.php, (7) serendipity_event_entryproperties/serendipity_event_entryproperties.php, (8) serendipity_event_karma/serendipity_event_karma.php, (9) serendipity_event_livesearch/serendipity_event_livesearch.php, (10) serendipity_event_mailer/serendipity_event_mailer.php, (11) serendipity_event_nl2br/serendipity_event_nl2br.php, (12) serendipity_event_s9ymarkup/serendipity_event_s9ymarkup.php, (13) serendipity_event_searchhighlight/serendipity_event_searchhighlight.php, (14) serendipity_event_spamblock/serendipity_event_spamblock.php, (15) serendipity_event_spartacus/serendipity_event_spartacus.php, (16) serendipity_event_statistics/serendipity_plugin_statistics.php, (17) serendipity_event_templatechooser/serendipity_event_templatechooser.php, (18) serendipity_event_textile/serendipity_event_textile.php, (19) serendipity_event_textwiki/serendipity_event_textwiki.php, (20) serendipity_event_trackexits/serendipity_event_trackexits.php, (21) serendipity_event_weblogping/serendipity_event_weblogping.php, (22) serendipity_event_xhtmlcleanup/serendipity_event_xhtmlcleanup.php, (23) serendipity_plugin_comments/serendipity_plugin_comments.php, (24) serendipity_plugin_creativecommons/serendipity_plugin_creativecommons.php, (25) serendipity_plugin_entrylinks/serendipity_plugin_entrylinks.php, (26) serendipity_plugin_eventwrapper/serendipity_plugin_eventwrapper.php, (27) serendipity_plugin_history/serendipity_plugin_history.php, (28) serendipity_plugin_recententries/serendipity_plugin_recententries.php, (29) serendipity_plugin_remoterss/serendipity_plugin_remoterss.php, (30) serendipity_plugin_shoutbox/serendipity_plugin_shoutbox.php, and and (31) serendipity_plugin_templatedropdown/serendipity_plugin_templatedropdown.php.","MILW0RM:2869 | URL:http://milw0rm.com/exploits/2869 | MISC:http://www.s9y.org/forums/viewtopic.php?t=7922 | BID:21367 | URL:http://www.securityfocus.com/bid/21367 | VUPEN:ADV-2006-4782 | URL:http://www.vupen.com/english/advisories/2006/4782 | XF:serendipity-lang-file-include(30615) | URL:http://xforce.iss.net/xforce/xfdb/30615",Assigned (20061203),"None (candidate not yet proposed)",
86| [CVE-2006-6271,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in PHPOLL 0.96 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) index.php, (2) info.php] and (3) index.php, (4) votanti.php, (5) risultati_config.php, (6) modifica_band.php, (7) band_editor.php, and (8) config_editor.php in admin/.","BUGTRAQ:20061119 PHPOLL => 0.96 Cross Site Scripting | URL:http://www.securityfocus.com/archive/1/archive/1/452093/100/200/threaded | SREASON:1960 | URL:http://securityreason.com/securityalert/1960 | XF:phpoll-language-xss(30426) | URL:http://xforce.iss.net/xforce/xfdb/30426",Assigned (20061203),"None (candidate not yet proposed)",
87| [CVE-2006-6422,Candidate,"Agileco AgileBill 1.4.x and AgileVoice 1.4.x do not properly handle certain proxy requests, which allows remote attackers to disable the application by entering invalid license data on a form, possibly involving modules/core/license.inc.php. NOTE: The provenance of this information is unknown] the details are obtained solely from third party information.","BID:21459 | URL:http://www.securityfocus.com/bid/21459 | SECUNIA:23223 | URL:http://secunia.com/advisories/23223 | XF:agilebill-proxy-dos(30751) | URL:http://xforce.iss.net/xforce/xfdb/30751",Assigned (20061209),"None (candidate not yet proposed)",
88| [CVE-2006-6424,Candidate,"Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow] and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow.","BUGTRAQ:20061223 ZDI-06-052: Novell NetMail NMAP STOR Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/455201/100/0/threaded | BUGTRAQ:20061223 ZDI-06-053: Novell NetMail IMAP Verb Literal Heap Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/455202/100/0/threaded | MISC:http://www.cirt.dk/advisories/cirt-48-advisory.txt | MISC:http://www.zerodayinitiative.com/advisories/ZDI-06-052.html | MISC:http://www.zerodayinitiative.com/advisories/ZDI-06-053.html | CONFIRM:https://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html | CERT-VN:VU#381161 | URL:http://www.kb.cert.org/vuls/id/381161 | CERT-VN:VU#912505 | URL:http://www.kb.cert.org/vuls/id/912505 | BID:21725 | URL:http://www.securityfocus.com/bid/21725 | BID:21724 | URL:http://www.securityfocus.com/bid/21724 | VUPEN:ADV-2006-5134 | URL:http://www.vupen.com/english/advisories/2006/5134 | SECTRACK:1017437 | URL:http://securitytracker.com/id?1017437 | SECUNIA:23437 | URL:http://secunia.com/advisories/23437 | SREASON:2081 | URL:http://securityreason.com/securityalert/2081",Assigned (20061209),"None (candidate not yet proposed)",
89| [CVE-2006-6466,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in WBmap.php in WikyBlog 1.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) key, (2) d, (3) l, or (4) v parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. NOTE: CVE disputes the l vector because l is validated by ctype_alpha before use.","VUPEN:ADV-2006-4823 | URL:http://www.vupen.com/english/advisories/2006/4823",Assigned (20061211),"None (candidate not yet proposed)",
90| [CVE-2006-6482,Candidate,"Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message] or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.","BUGTRAQ:20061210 [SBDA] - ColdFusion MX7 - Multiple Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/454046/100/0/threaded | BID:21532 | URL:http://www.securityfocus.com/bid/21532 | VUPEN:ADV-2006-4949 | URL:http://www.vupen.com/english/advisories/2006/4949 | SECTRACK:1017361 | URL:http://securitytracker.com/id?1017361 | SECUNIA:23281 | URL:http://secunia.com/advisories/23281 | SREASON:2021 | URL:http://securityreason.com/securityalert/2021 | XF:coldfusion-extensions-path-disclosure(30839) | URL:http://xforce.iss.net/xforce/xfdb/30839 | XF:coldfusion-login-information-disclosure(30840) | URL:http://xforce.iss.net/xforce/xfdb/30840",Assigned (20061212),"None (candidate not yet proposed)",
91| [CVE-2006-6599,Candidate,"maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (""] "" semicolon) in the announce parameter.","MILW0RM:2903 | URL:http://milw0rm.com/exploits/2903 | BID:21526 | URL:http://www.securityfocus.com/bid/21526 | SECUNIA:23270 | URL:http://secunia.com/advisories/23270 | XF:torrentflux-maketorrent-command-execution(30850) | URL:http://xforce.iss.net/xforce/xfdb/30850",Assigned (20061215),"None (candidate not yet proposed)",
92| [CVE-2006-6740,Candidate,"Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php] or a URL in the incpath parameter to (3) index.inc.php, (4) account.inc.php, (5) admin_newcomm.inc.php, (6) header_admin.inc.php, (7) header.inc.php, (8) friends.inc.php, (9) menu_u.inc.php, (10) notify.inc.php, (11) body.inc.php, (12) body_admin.inc.php, (13) commrecc.inc.php, (14) do_reg.inc.php, (15) comm_post.inc.php, or (16) menu_v.inc.php in include/, different vectors than CVE-2006-5634. NOTE: The provenance of this information is unknown
93| [CVE-2006-6828,Candidate,"Multiple SQL injection vulnerabilities in Efkan Forum 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the grup parameter in admin.asp, or the id parameter in (2) default.asp or (3) admin.asp. NOTE: The provenance of this information is unknown] the details are obtained solely from third party information. The default.asp/grup vector is already covered by CVE-2006-6794.","VUPEN:ADV-2006-5150 | URL:http://www.vupen.com/english/advisories/2006/5150",Assigned (20070101),"None (candidate not yet proposed)",
94| [CVE-2006-7103,Candidate,"Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a "".."" in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence] and read arbitrary image files via a "".."" in the album or (2) image parameter to (b) image.php.","BUGTRAQ:20061027 MHL-2006-003 Public Advisory: ""ezOnlineGallery"" Multiple Security Issues | URL:http://www.securityfocus.com/archive/1/archive/1/449889/100/0/threaded | FULLDISC:20061027 MHL-2006-003 Public Advisory: ""ezOnlineGallery"" Multiple Security Issues | URL:http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050364.html | MISC:http://www.mayhemiclabs.com/advisories/MHL-2006-003.txt | CONFIRM:http://www.ezonlinegallery.com/changelog.txt | BID:20763 | URL:http://www.securityfocus.com/bid/20763 | SREASON:2362 | URL:http://securityreason.com/securityalert/2362 | XF:ezonlinegallery-image-directory-traversal(29836) | URL:http://xforce.iss.net/xforce/xfdb/29836 | XF:ezonlinegallery-ezgallery-path-disclosure(29835) | URL:http://xforce.iss.net/xforce/xfdb/29835",Assigned (20070303),"None (candidate not yet proposed)",
95| [CVE-2007-0018,Candidate,"Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice] (2) Magic Audio Recorder, Music Editor, and Audio Converter
96| [CVE-2007-0038,Candidate,"Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765] if so, then CVE-2007-0038 should be preferred.","BUGTRAQ:20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038) | URL:http://www.securityfocus.com/archive/1/archive/1/464269/100/0/threaded | BUGTRAQ:20070330 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038) | URL:http://www.securityfocus.com/archive/1/archive/1/464339/100/0/threaded | BUGTRAQ:20070331 RE: [Full-disclosure] 0-day ANI vulnerability in Microsoft Windows(CVE-2007-0038) | URL:http://www.securityfocus.com/archive/1/archive/1/464342/100/0/threaded | BUGTRAQ:20070331 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038) | URL:http://www.securityfocus.com/archive/1/archive/1/464340/100/0/threaded | BUGTRAQ:20070402 More information on ZERT patch for ANI 0day | URL:http://www.securityfocus.com/archive/1/archive/1/464459/100/100/threaded | BUGTRAQ:20070402 MS announces out-of-band patch for ANI 0day | URL:http://www.securityfocus.com/archive/1/archive/1/464460/100/100/threaded | FULLDISC:20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038) | URL:http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html | MILW0RM:3634 | URL:http://milw0rm.com/exploits/3634 | MISC:http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp | HP:HPSBST02206 | URL:http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded | HP:SSRT071354 | URL:http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded | MS:MS07-017 | URL:http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx | CERT:TA07-089A | URL:http://www.us-cert.gov/cas/techalerts/TA07-089A.html | CERT:TA07-093A | URL:http://www.us-cert.gov/cas/techalerts/TA07-093A.html | CERT:TA07-100A | URL:http://www.us-cert.gov/cas/techalerts/TA07-100A.html | CERT-VN:VU#191609 | URL:http://www.kb.cert.org/vuls/id/191609 | VUPEN:ADV-2007-1215 | URL:http://www.vupen.com/english/advisories/2007/1215 | OSVDB:33629 | URL:http://www.osvdb.org/33629 | OVAL:oval:org.mitre.oval:def:1854 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1854 | SECUNIA:24659 | URL:http://secunia.com/advisories/24659 | SREASON:2542 | URL:http://securityreason.com/securityalert/2542 | XF:windows-ani-code-execution(33301) | URL:http://xforce.iss.net/xforce/xfdb/33301 | XF:win-ani-code-execution(33301) | URL:http://xforce.iss.net/xforce/xfdb/33301",Assigned (20070103),"None (candidate not yet proposed)",
97| [CVE-2007-0055,Candidate,"Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the Name parameter. NOTE: The provenance of this information is unknown] the details are obtained solely from third party information.","MILW0RM:3063 | URL:http://milw0rm.com/exploits/3063 | VUPEN:ADV-2007-0012 | URL:http://www.vupen.com/english/advisories/2007/0012 | OSVDB:32545 | URL:http://osvdb.org/32545 | SECUNIA:23539 | URL:http://secunia.com/advisories/23539 | XF:formbankserver-name-directory-traversal(31214) | URL:http://xforce.iss.net/xforce/xfdb/31214",Assigned (20070104),"None (candidate not yet proposed)",
98| [CVE-2007-0437,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in csp/samples/] and allow remote authenticated users to inject arbitrary web script or HTML via (4) the ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/.","MISC:http://www.cpni.gov.uk/Products/alerts/2928.aspx | MISC:http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf | MISC:http://www.mwrinfosecurity.com/news/1658.html",Assigned (20070123),"None (candidate not yet proposed)",
99| [CVE-2007-0513,Candidate,"Hitachi HiRDB Datareplicator 7HiRDB, 7(64), 6, 6(64), 5.0, and 5.0(64)] and various products that bundle HiRDB Datareplicator
100| [CVE-2007-1042,Candidate,"Directory traversal vulnerability in news.php in Xpression News (X-News) 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","OSVDB:33226 | URL:http://osvdb.org/33226 | SECUNIA:24177 | URL:http://secunia.com/advisories/24177 | XF:xnews-archives-news-directory-traversal(32560) | URL:http://xforce.iss.net/xforce/xfdb/32560",Assigned (20070221),"None (candidate not yet proposed)",
101| [CVE-2007-1145,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user's name in index.php] and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.","BUGTRAQ:20070219 ESupport Multiple HTML Injection Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/460591/100/0/threaded | BID:22631 | URL:http://www.securityfocus.com/bid/22631 | VUPEN:ADV-2007-0717 | URL:http://www.vupen.com/english/advisories/2007/0717 | OSVDB:33535 | URL:http://osvdb.org/33535 | OSVDB:33536 | URL:http://osvdb.org/33536 | SECUNIA:24223 | URL:http://secunia.com/advisories/24223 | SREASON:2335 | URL:http://securityreason.com/securityalert/2335",Assigned (20070227),"None (candidate not yet proposed)",
102| [CVE-2007-1321,Candidate,"Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 ""receive"" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled ""NE2000 network driver and the socket code,"" but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes] see CVE-2007-5729 and CVE-2007-5730.","MISC:http://taviso.decsystem.org/virtsec.pdf | DEBIAN:DSA-1284 | URL:http://www.debian.org/security/2007/dsa-1284 | FEDORA:FEDORA-2007-2270 | URL:https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00030.html | FEDORA:FEDORA-2007-713 | URL:https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.html | FEDORA:FEDORA-2007-2708 | URL:https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00004.html | MANDRIVA:MDKSA-2007:203 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:203 | MANDRIVA:MDVSA-2008:162 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:162 | REDHAT:RHSA-2007:0323 | URL:http://www.redhat.com/support/errata/RHSA-2007-0323.html | VIM:20071030 Clarification on old QEMU/NE2000/Xen issues | URL:http://www.attrition.org/pipermail/vim/2007-October/001842.html | BID:23731 | URL:http://www.securityfocus.com/bid/23731 | OSVDB:35495 | URL:http://osvdb.org/35495 | OVAL:oval:org.mitre.oval:def:9302 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9302 | VUPEN:ADV-2007-1597 | URL:http://www.vupen.com/english/advisories/2007/1597 | SECTRACK:1018761 | URL:http://securitytracker.com/id?1018761 | SECUNIA:27072 | URL:http://secunia.com/advisories/27072 | SECUNIA:27103 | URL:http://secunia.com/advisories/27103 | SECUNIA:27486 | URL:http://secunia.com/advisories/27486 | SECUNIA:25073 | URL:http://secunia.com/advisories/25073 | SECUNIA:25095 | URL:http://secunia.com/advisories/25095 | SECUNIA:27047 | URL:http://secunia.com/advisories/27047 | SECUNIA:29129 | URL:http://secunia.com/advisories/29129",Assigned (20070307),"None (candidate not yet proposed)",
103| [CVE-2007-1732,Candidate,"** DISPUTED ** Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stating that this is legitimate functionality for administrators. However, it has been patched by at least one vendor.","BUGTRAQ:20070306 Re: Wordpress <= v2.1.0 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=117319839710382&w=2 | MISC:http://codex.wordpress.org/Roles_and_Capabilities | GENTOO:GLSA-200703-23 | URL:http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml | OSVDB:33884 | URL:http://osvdb.org/33884 | SECUNIA:24430 | URL:http://secunia.com/advisories/24430 | SECUNIA:24566 | URL:http://secunia.com/advisories/24566",Assigned (20070328),"None (candidate not yet proposed)",
104| [CVE-2007-1804,Candidate,"PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion failure in do_read] (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a length assertion failure in pa_memblock_new
105| [CVE-2007-2097,Candidate,"** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End CMS 0.4.7 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter to (1) click.php or (2) pollcollector.php in htdocs/] or (3) index.php, (4) articlepages.php, (5) articles.php, (6) articleform.php, (7) articlesections.php, (8) createArticlesPage.php, (9) guestbook.php, (10) helpguide.php, (11) helpguideeditor.php, (12) links.php, (13) upload.php, (14) sitestatistics.php, (15) nav.php, (16) tpl_upload.php, (17) linksections, or (18) pophelp.php in htdocs/site-admin/
106| [CVE-2007-2362,Candidate,"Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and possibly execute arbitrary code via a certain update, which triggers a heap-based buffer overflow in update.c] and (2) cause a denial of service (daemon crash) via unspecified vectors that trigger an off-by-one stack-based buffer overflow in update.c.","FULLDISC:20070427 mydns-1.1.0 remote heap overflow | URL:http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/054024.html | MISC:http://www.digit-labs.org/files/exploits/mydns-rr-smash.c | MISC:http://www.digit-labs.org/files/patches/mydns-update.c.diff | DEBIAN:DSA-1434 | URL:http://www.debian.org/security/2007/dsa-1434 | BID:23694 | URL:http://www.securityfocus.com/bid/23694 | VUPEN:ADV-2007-1561 | URL:http://www.vupen.com/english/advisories/2007/1561 | OSVDB:35438 | URL:http://osvdb.org/35438 | OSVDB:35439 | URL:http://osvdb.org/35439 | SECUNIA:25007 | URL:http://secunia.com/advisories/25007 | SECUNIA:28086 | URL:http://secunia.com/advisories/28086 | SREASON:2658 | URL:http://securityreason.com/securityalert/2658 | XF:mydns-update-bo(33933) | URL:http://xforce.iss.net/xforce/xfdb/33933",Assigned (20070430),"None (candidate not yet proposed)",
107| [CVE-2007-2599,Candidate,"Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php] the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php
108| [CVE-2007-2600,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php] the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php
109| [CVE-2007-2651,Candidate,"Multiple off-by-one errors in VooDoo cIRCle before 1.1.beta27 allow remote attackers to cause a denial of service (connection loss) or possibly execute arbitrary code via a (1) DNS name response of the exact length as a buffer] or a long (2) channel name, (3) partyline channel name, or unspecified vectors in crafted BOTNET packets.","CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=497807&group_id=116847 | BID:23929 | URL:http://www.securityfocus.com/bid/23929 | VUPEN:ADV-2007-1756 | URL:http://www.vupen.com/english/advisories/2007/1756 | OSVDB:41985 | URL:http://osvdb.org/41985 | OSVDB:41986 | URL:http://osvdb.org/41986 | XF:voodoocircle-ssl-dos(34229) | URL:http://xforce.iss.net/xforce/xfdb/34229",Assigned (20070514),"None (candidate not yet proposed)",
110| [CVE-2007-2721,Candidate,"The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.","CONFIRM:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413033 | CONFIRM:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413041 | CONFIRM:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413041] msg=88 | DEBIAN:DSA-2036 | URL:http://www.debian.org/security/2010/dsa-2036 | MANDRIVA:MDKSA-2007:129 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:129 | MANDRIVA:MDKSA-2007:209 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:209 | MANDRIVA:MDKSA-2007:208 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:208 | MANDRIVA:MDVSA-2009:142 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:142 | MANDRIVA:MDVSA-2009:164 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:164 | REDHAT:RHSA-2009:0012 | URL:http://www.redhat.com/support/errata/RHSA-2009-0012.html | UBUNTU:USN-501-1 | URL:http://www.ubuntu.com/usn/usn-501-1 | UBUNTU:USN-501-2 | URL:http://www.ubuntu.com/usn/usn-501-2 | BID:24052 | URL:http://www.securityfocus.com/bid/24052 | OSVDB:36137 | URL:http://osvdb.org/36137 | OVAL:oval:org.mitre.oval:def:9397 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9397 | SECUNIA:25287 | URL:http://secunia.com/advisories/25287 | SECUNIA:25703 | URL:http://secunia.com/advisories/25703 | SECUNIA:26516 | URL:http://secunia.com/advisories/26516 | SECUNIA:27319 | URL:http://secunia.com/advisories/27319 | SECUNIA:27489 | URL:http://secunia.com/advisories/27489 | SECUNIA:39505 | URL:http://secunia.com/advisories/39505 | VUPEN:ADV-2010-0912 | URL:http://www.vupen.com/english/advisories/2010/0912",Assigned (20070516),"None (candidate not yet proposed)",
111| [CVE-2007-3066,Candidate,"Multiple PHP remote file inclusion vulnerabilities in php(Reactor) 1.2.7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter to (1) view.inc.php, (2) users.inc.php, (3) updatecms.inc.php, and (4) polls.inc.php in inc/] and other unspecified files, different vectors than CVE-2006-3983.","BUGTRAQ:20070601 phpreactor <===1.2.7 remote file include | URL:http://www.securityfocus.com/archive/1/archive/1/470241/100/0/threaded | OSVDB:38375 | URL:http://osvdb.org/38375 | OSVDB:38376 | URL:http://osvdb.org/38376 | OSVDB:38377 | URL:http://osvdb.org/38377 | OSVDB:38378 | URL:http://osvdb.org/38378 | SREASON:2773 | URL:http://securityreason.com/securityalert/2773 | XF:phpreactor-pathtohomedir-file-include(34674) | URL:http://xforce.iss.net/xforce/xfdb/34674",Assigned (20070605),"None (candidate not yet proposed)",
112| [CVE-2007-3253,Candidate,"Multiple unspecified vulnerabilities in Astaro Security Gateway (ASG) before 7.005 allow remote attackers to cause a denial of service via (1) certain email, which stops the SMTP Proxy during scanning] (2) certain HTTP traffic, which stops or slows down the HTTP proxy during HTTP responses containing virus scanned web pages
113| [CVE-2007-3639,Candidate,"WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php] and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.","BUGTRAQ:20070705 Redirection Vulnerability in wp-pass.php, WordPress 2.2.1 | URL:http://www.securityfocus.com/archive/1/archive/1/472885/100/0/threaded | DEBIAN:DSA-1564 | URL:http://www.debian.org/security/2008/dsa-1564 | OSVDB:40802 | URL:http://osvdb.org/40802 | SECUNIA:30013 | URL:http://secunia.com/advisories/30013 | SREASON:2869 | URL:http://securityreason.com/securityalert/2869 | XF:wordpress-wppass-security-bypass(35272) | URL:http://xforce.iss.net/xforce/xfdb/35272",Assigned (20070709),"None (candidate not yet proposed)",
114| [CVE-2007-3714,Candidate,"Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter to the default URI. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. NOTE: this is probably a different issue than CVE-2004-2464. NOTE: it was later reported that 0.6.21 and earlier is also affected.","BUGTRAQ:20071224 Double directory traversal in ImgSvr 0.6.21 | URL:http://www.securityfocus.com/archive/1/archive/1/485490/100/100/threaded | BID:24853 | URL:http://www.securityfocus.com/bid/24853 | OSVDB:38083 | URL:http://osvdb.org/38083 | SECUNIA:26000 | URL:http://secunia.com/advisories/26000",Assigned (20070711),"None (candidate not yet proposed)",
115| [CVE-2007-3822,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser] and other vectors involving (2) calendar mode, (3) bulletin board mode, (4) room names, and (5) uploaded file names.","BUGTRAQ:20070714 Session Riding and multiple XSS in WebCit | URL:http://www.securityfocus.com/archive/1/archive/1/473714/100/0/threaded | BID:24913 | URL:http://www.securityfocus.com/bid/24913 | OSVDB:38176 | URL:http://osvdb.org/38176 | OSVDB:38177 | URL:http://osvdb.org/38177 | OSVDB:38178 | URL:http://osvdb.org/38178 | OSVDB:38179 | URL:http://osvdb.org/38179 | OSVDB:38180 | URL:http://osvdb.org/38180 | SECUNIA:26090 | URL:http://secunia.com/advisories/26090 | SREASON:2890 | URL:http://securityreason.com/securityalert/2890 | XF:webcit-multiple-xss(35433) | URL:http://xforce.iss.net/xforce/xfdb/35433",Assigned (20070716),"None (candidate not yet proposed)",
116| [CVE-2007-3989,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in default.asp in Dora Emlak 1.0, when the goster parameter is set to iletisim, allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz and (2) Soyadiniz parameters] and possibly other unspecified vectors. NOTE: the provenance of this information is unknown
117| [CVE-2007-3991,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in cv.asp in Asp cvmatik 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz (Ady), (2) Soyadiniz (Soyady), (3) Ehliyet, (4) Askerlik, and (5) GSM parameters] and possibly other unspecified vectors.","MISC:http://downloads.securityfocus.com/vulnerabilities/exploits/25008.html | BID:25008 | URL:http://www.securityfocus.com/bid/25008 | VUPEN:ADV-2007-2604 | URL:http://www.vupen.com/english/advisories/2007/2604 | OSVDB:36471 | URL:http://osvdb.org/36471 | SECUNIA:26174 | URL:http://secunia.com/advisories/26174",Assigned (20070725),"None (candidate not yet proposed)",
118| [CVE-2007-4011,Candidate,"Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software before 3.2 20070727, 4.0 before 20070727, and 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (traffic amplification or ARP storm) via a crafted unicast ARP request that (1) has a destination MAC address unknown to the Layer-2 infrastructure, aka CSCsj69233] or (2) occurs during Layer-3 roaming across IP subnets, aka CSCsj70841.","CISCO:20070724 Wireless ARP Storm Vulnerability | URL:http://www.cisco.com/en/US/products/products_security_advisory09186a008088ab28.shtml | BID:25043 | URL:http://www.securityfocus.com/bid/25043 | VUPEN:ADV-2007-2636 | URL:http://www.vupen.com/english/advisories/2007/2636 | SECTRACK:1018444 | URL:http://www.securitytracker.com/id?1018444 | SECUNIA:26161 | URL:http://secunia.com/advisories/26161 | XF:cisco-wlc-arp-dos(35576) | URL:http://xforce.iss.net/xforce/xfdb/35576",Assigned (20070725),"None (candidate not yet proposed)",
119| [CVE-2007-4035,Candidate,"** DISPUTED ** Guidance Software EnCase does not properly handle (1) certain malformed MBR partition tables with many entries, which allows remote attackers to prevent logical collection of a disk image] (2) NTFS filesystems with directory loops, which allows remote attackers to prevent examination of certain directory contents
120| [CVE-2007-4064,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via ""some server variables,"" including PHP_SELF] and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.","CONFIRM:http://drupal.org/files/sa-2007-018/advisory.txt | BID:25097 | URL:http://www.securityfocus.com/bid/25097 | VUPEN:ADV-2007-2697 | URL:http://www.vupen.com/english/advisories/2007/2697 | SECUNIA:26224 | URL:http://secunia.com/advisories/26224 | XF:drupal-contenttype-xss(35637) | URL:http://xforce.iss.net/xforce/xfdb/35637 | XF:drupal-servervariable-xss(35638) | URL:http://xforce.iss.net/xforce/xfdb/35638",Assigned (20070730),"None (candidate not yet proposed)",
121| [CVE-2007-4150,Candidate,"The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak cryptography (XOR) when (1) transmitting passwords, which allows remote attackers to obtain sensitive information by sniffing the network] and (2) storing passwords in the configuration file, which allows local users to obtain sensitive information by reading this file.","MISC:http://www.portcullis.co.uk/uplds/advisories/vapassword%20-%2006-042.txt | BID:25153 | URL:http://www.securityfocus.com/bid/25153 | OSVDB:46979 | URL:http://osvdb.org/46979",Assigned (20070803),"None (candidate not yet proposed)",
122| [CVE-2007-4153,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php] or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.","MISC:http://codex.wordpress.org/Roles_and_Capabilities | MISC:http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nearly_wrote_the_first_blog_worm/ | DEBIAN:DSA-1564 | URL:http://www.debian.org/security/2008/dsa-1564 | OSVDB:46994 | URL:http://osvdb.org/46994 | OSVDB:46995 | URL:http://osvdb.org/46995 | SECUNIA:30013 | URL:http://secunia.com/advisories/30013 | XF:wordpress-linkimport-xss(35720) | URL:http://xforce.iss.net/xforce/xfdb/35720 | XF:wordpress-options-xss(35722) | URL:http://xforce.iss.net/xforce/xfdb/35722",Assigned (20070803),"None (candidate not yet proposed)",
123| [CVE-2007-4221,Candidate,"Multiple buffer overflows in Motorola Timbuktu Pro before 8.6.5 for Windows allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via (1) a long user name and (2) certain malformed requests] and (3) allow remote Timbuktu servers to have an unknown impact via a malformed HELLO response, related to the Scanner component and possibly related to a malformed computer name.","IDEFENSE:20070827 Motorola Timbuktu Multiple Buffer Overflow Vulnerabilities | URL:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=590 | CONFIRM:ftp://ftp-xo.netopia.com/evaluation/docs/timbuktu/win/865/relnotes/TB2Win865Evalrn.pdf | BID:25454 | URL:http://www.securityfocus.com/bid/25454 | VUPEN:ADV-2007-2990 | URL:http://www.vupen.com/english/advisories/2007/2990 | SECTRACK:1018614 | URL:http://www.securitytracker.com/id?1018614 | SECUNIA:26588 | URL:http://secunia.com/advisories/26588 | XF:timbuktu-login-bo(36281) | URL:http://xforce.iss.net/xforce/xfdb/36281 | XF:timbuktu-protocol-bo(36280) | URL:http://xforce.iss.net/xforce/xfdb/36280 | XF:timbuktu-scanner-bo(36282) | URL:http://xforce.iss.net/xforce/xfdb/36282",Assigned (20070808),"None (candidate not yet proposed)",
124| [CVE-2007-4291,Candidate,"Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service via (1) a malformed MGCP packet, which causes a device hang, aka CSCsf08998] a malformed H.323 packet, which causes a device crash, as identified by (2) CSCsi60004 with Proxy Unregistration and (3) CSCsg70474
125| [CVE-2007-4293,Candidate,"Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device crash) via (1) ""abnormal"" MGCP messages, aka CSCsd81407] and (2) a large facsimile packet, aka CSCej20505.","CISCO:20070808 Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager | URL:http://www.cisco.com/en/US/products/products_security_advisory09186a0080899653.shtml | BID:25239 | URL:http://www.securityfocus.com/bid/25239 | OVAL:oval:org.mitre.oval:def:5801 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5801 | VUPEN:ADV-2007-2816 | URL:http://www.vupen.com/english/advisories/2007/2816 | OSVDB:36668 | URL:http://osvdb.org/36668 | OSVDB:36669 | URL:http://osvdb.org/36669 | SECTRACK:1018533 | URL:http://securitytracker.com/id?1018533 | SECUNIA:26363 | URL:http://secunia.com/advisories/26363 | XF:cisco-ios-facsimile-dos(35907) | URL:http://xforce.iss.net/xforce/xfdb/35907",Assigned (20070809),"None (candidate not yet proposed)",
126| [CVE-2007-4404,Candidate,"ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two channels with certain long names that differ in the final character, which triggers a protocol violation and (2) cause a denial of service (daemon crash) via a ""J 0:#channel"" message on a channel without an apass] and (3) allows remote authenticated operators to cause a denial of service (daemon crash) via a remote ""names -D"" command.","BUGTRAQ:20070812 Multiple vulnerabilities in ircu | URL:http://www.securityfocus.com/archive/1/archive/1/476285/100/0/threaded | BID:25285 | URL:http://www.securityfocus.com/bid/25285 | OSVDB:46710 | URL:http://osvdb.org/46710 | OSVDB:46711 | URL:http://osvdb.org/46711 | OSVDB:46712 | URL:http://osvdb.org/46712 | SREASON:3031 | URL:http://securityreason.com/securityalert/3031 | XF:ircu-channelname-dos(35986) | URL:http://xforce.iss.net/xforce/xfdb/35986 | XF:ircu-joinapass-dos(35987) | URL:http://xforce.iss.net/xforce/xfdb/35987 | XF:ircu-remotenames-dos(35984) | URL:http://xforce.iss.net/xforce/xfdb/35984",Assigned (20070818),"None (candidate not yet proposed)",
127| [CVE-2007-4436,Candidate,"The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote attackers to (1) obtain sensitive via the Tracker Module and the Recent posts page] (2) obtain project names via unspecified vectors
128| [CVE-2007-4445,Candidate,"Image Space rFactor 1.250 and earlier allows remote attackers to cause a denial of service (daemon crash) via (1) an ID 0x30 packet, (2) an ID 0x38 packet, and an invalid 13-bit integer in (3) an ID 0x60 packet and (4) an ID 0x68 packet] and a denial of service (UDP port block) via (5) an ID 0x20 packet and (6) an ID 0x28 packet.","BUGTRAQ:20070818 Multiple vulnerabilities in rFactor 1.250 | URL:http://www.securityfocus.com/archive/1/archive/1/477023/100/0/threaded | BUGTRAQ:20070925 Re: Multiple vulnerabilities in rFactor 1.250 | URL:http://www.securityfocus.com/archive/1/archive/1/480591/100/200/threaded | BUGTRAQ:20070927 Re: Multiple vulnerabilities in rFactor 1.250 | URL:http://www.securityfocus.com/archive/1/archive/1/480921/100/200/threaded | MISC:http://aluigi.org/poc/rfactorx.zip | CONFIRM:http://forum.racesimcentral.com/showthread.php?t=298659 | CONFIRM:http://www.rfactor.net/?page=news_09-26_1255 | BID:25358 | URL:http://www.securityfocus.com/bid/25358 | SECUNIA:26526 | URL:http://secunia.com/advisories/26526 | SREASON:3037 | URL:http://securityreason.com/securityalert/3037 | XF:rfactor-ids-dos(36094) | URL:http://xforce.iss.net/xforce/xfdb/36094 | XF:rfactor-ids-udp-dos(36095) | URL:http://xforce.iss.net/xforce/xfdb/36095",Assigned (20070820),"None (candidate not yet proposed)",
129| [CVE-2007-4447,Candidate,"Multiple buffer overflows in the client in Toribash 2.71 and earlier allow remote attackers to (1) execute arbitrary code via a long game command in a replay (.rpl) file and (2) cause a denial of service (application crash) via a long SAY command that omits a required LF character] and allow remote Toribash servers to execute arbitrary code via (3) a long game command and (4) a long SAY command that omits a required LF character.","BUGTRAQ:20070818 Multiple vulnerabilities in Toribash 2.71 | URL:http://www.securityfocus.com/archive/1/archive/1/477025/100/0/threaded | MISC:http://aluigi.org/poc/toribashish.zip | BID:25359 | URL:http://www.securityfocus.com/bid/25359 | SECUNIA:26507 | URL:http://secunia.com/advisories/26507 | SREASON:3033 | URL:http://securityreason.com/securityalert/3033 | XF:toribash-say-bo(36097) | URL:http://xforce.iss.net/xforce/xfdb/36097",Assigned (20070820),"None (candidate not yet proposed)",
130| [CVE-2007-4485,Candidate,"PHP remote file inclusion vulnerability in visitor.php in Butterfly online visitors counter 1.08, when used with certain older versions of PHP with improper SERVER superglobal handling, allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. NOTE: it could be argued that this vulnerability is caused by a problem in PHP and the proper fix should be in PHP] if so, then this should not be treated as a vulnerability in Butterfly online visitors counter.","BUGTRAQ:20070821 Vulnerabilities digest | URL:http://www.securityfocus.com/archive/1/archive/1/477253/100/0/threaded | BUGTRAQ:20071010 Vulnerabilities digest | URL:http://www.securityfocus.com/archive/1/archive/1/482006/100/0/threaded | MISC:http://securityvulns.com/Rdocument845.html | MISC:http://securityvulns.com/source26994.html | OSVDB:38327 | URL:http://osvdb.org/38327 | XF:butterfly-visitor-file-include(36147) | URL:http://xforce.iss.net/xforce/xfdb/36147",Assigned (20070822),"None (candidate not yet proposed)",
131| [CVE-2007-4589,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Webmaster Level (SiteWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php] and allow remote authenticated users to inject arbitrary web script or HTML via the PATH_INFO to (2) siteworx.php, (3) users.php, (4) ftp.php, (5) mysql.php, (6) domains.php, (7) htaccess.php, (8) scriptworx.php, (9) stats.php, (10) backup.php, (11) restore.php, and (12) httpd.php
132| [CVE-2007-4738,Candidate,"Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) db_conf or (2) ADODB_DIR parameter to utils/stphpimage_show.php] or a URL in the STPHPLIB_DIR parameter to (3) stphpbutton.php, (4) stphpcheckbox.php, (5) stphpcheckboxwithcaption.php, (6) stphpcheckgroup.php, (7) stphpcomponent.php, (8) stphpcontrolwithcaption.php, (9) stphpedit.php, (10) stphpeditwithcaption.php, (11) stphphr.php, (12) stphpimage.php, (13) stphpimagewithcaption.php, (14) stphplabel.php, (15) stphplistbox.php, (16) stphplistboxwithcaption.php, (17) stphplocale.php, (18) stphppanel.php, (19) stphpradiobutton.php, (20) stphpradiobuttonwithcaption.php, (21) stphpradiogroup.php, (22) stphprichbutton.php, (23) stphpspacer.php, (24) stphptable.php, (25) stphptablecell.php, (26) stphptablerow.php, (27) stphptabpanel.php, (28) stphptabtitle.php, (29) stphptextarea.php, (30) stphptextareawithcaption.php, (31) stphptoolbar.php, (32) stphpwindow.php, (33) stphpxmldoc.php, or (34) stphpxmlelement.php, a different set of vectors than CVE-2007-4737. NOTE: the provenance of this information is unknown
133| [CVE-2007-4764,Candidate,"Directory traversal vulnerability in pawfaliki.php in Pawfaliki 0.5.1 allows remote attackers to list arbitrary files via a .. (dot dot) in the page parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:25553 | URL:http://www.securityfocus.com/bid/25553 | OSVDB:38417 | URL:http://osvdb.org/38417 | SECUNIA:26702 | URL:http://secunia.com/advisories/26702 | XF:pawfaliki-pawfaliki-directory-traversal(36454) | URL:http://xforce.iss.net/xforce/xfdb/36454",Assigned (20070907),"None (candidate not yet proposed)",
134| [CVE-2007-4782,Candidate,"PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function] or (2) a long string in the string parameter to the fnmatch function, accompanied by a pattern parameter value with undefined characteristics, as demonstrated by a ""*[1]e"" value. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.","BUGTRAQ:20070904 PHP < 5.2.3 fnmatch() denial of service | URL:http://www.securityfocus.com/archive/1/archive/1/478630/100/0/threaded | BUGTRAQ:20070904 PHP < 5.2.3 glob() denial of service | URL:http://www.securityfocus.com/archive/1/archive/1/478626/100/0/threaded | BUGTRAQ:20070905 PHP < 5.2.3 glob() denial of service | URL:http://www.securityfocus.com/archive/1/478726/100/0/threaded | FEDORA:FEDORA-2008-3864 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00773.html | GENTOO:GLSA-200710-02 | URL:http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml | MANDRIVA:MDVSA-2009:022 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:022 | MANDRIVA:MDVSA-2009:023 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:023 | REDHAT:RHSA-2008:0505 | URL:http://www.redhat.com/support/errata/RHSA-2008-0505.html | REDHAT:RHSA-2008:0544 | URL:http://www.redhat.com/support/errata/RHSA-2008-0544.html | REDHAT:RHSA-2008:0545 | URL:http://www.redhat.com/support/errata/RHSA-2008-0545.html | REDHAT:RHSA-2008:0582 | URL:http://www.redhat.com/support/errata/RHSA-2008-0582.html | SUSE:SUSE-SA:2008:004 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html | UBUNTU:USN-628-1 | URL:http://www.ubuntu.com/usn/usn-628-1 | OSVDB:38686 | URL:http://osvdb.org/38686 | OVAL:oval:org.mitre.oval:def:10897 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10897 | SECUNIA:27102 | URL:http://secunia.com/advisories/27102 | SECUNIA:28658 | URL:http://secunia.com/advisories/28658 | SECUNIA:30828 | URL:http://secunia.com/advisories/30828 | SECUNIA:31119 | URL:http://secunia.com/advisories/31119 | SECUNIA:31200 | URL:http://secunia.com/advisories/31200 | SREASON:3109 | URL:http://securityreason.com/securityalert/3109 | XF:php-fnmatch-dos(36457) | URL:http://xforce.iss.net/xforce/xfdb/36457 | XF:php-globfunction-dos(36461) | URL:http://xforce.iss.net/xforce/xfdb/36461",Assigned (20070910),"None (candidate not yet proposed)",
135| [CVE-2007-4985,Candidate,"ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlobByte function calls] or (2) an infinite loop in the ReadXCFImage function, related to ReadBlobMSBLong function calls.","IDEFENSE:20070919 Multiple Vendor ImageMagick Multiple Denial of Service Vulnerabilities | URL:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=596 | BUGTRAQ:20071112 FLEA-2007-0066-1 ImageMagick | URL:http://www.securityfocus.com/archive/1/archive/1/483572/100/0/threaded | MLIST:[Magick-announce] 20070917 ImageMagick 6.3.5-9, important security updates | URL:http://studio.imagemagick.org/pipermail/magick-announce/2007-September/000037.html | CONFIRM:http://www.imagemagick.org/script/changelog.php | CONFIRM:https://issues.rpath.com/browse/RPL-1743 | CONFIRM:http://bugs.gentoo.org/show_bug.cgi?id=186030 | DEBIAN:DSA-1858 | URL:http://www.debian.org/security/2009/dsa-1858 | GENTOO:GLSA-200710-27 | URL:http://security.gentoo.org/glsa/glsa-200710-27.xml | MANDRIVA:MDVSA-2008:035 | URL:http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:035 | REDHAT:RHSA-2008:0145 | URL:http://www.redhat.com/support/errata/RHSA-2008-0145.html | REDHAT:RHSA-2008:0165 | URL:http://www.redhat.com/support/errata/RHSA-2008-0165.html | SUSE:SUSE-SR:2007:023 | URL:http://www.novell.com/linux/security/advisories/2007_23_sr.html | UBUNTU:USN-523-1 | URL:http://www.ubuntu.com/usn/usn-523-1 | BID:25764 | URL:http://www.securityfocus.com/bid/25764 | OVAL:oval:org.mitre.oval:def:10869 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10869 | SECUNIA:36260 | URL:http://secunia.com/advisories/36260 | VUPEN:ADV-2007-3245 | URL:http://www.vupen.com/english/advisories/2007/3245 | SECTRACK:1018729 | URL:http://www.securitytracker.com/id?1018729 | SECUNIA:26926 | URL:http://secunia.com/advisories/26926 | SECUNIA:27048 | URL:http://secunia.com/advisories/27048 | SECUNIA:27309 | URL:http://secunia.com/advisories/27309 | SECUNIA:27364 | URL:http://secunia.com/advisories/27364 | SECUNIA:27439 | URL:http://secunia.com/advisories/27439 | SECUNIA:28721 | URL:http://secunia.com/advisories/28721 | SECUNIA:29786 | URL:http://secunia.com/advisories/29786 | SECUNIA:29857 | URL:http://secunia.com/advisories/29857 | XF:imagemagick-readdcmimage-readxcfimage-dos(36740) | URL:http://xforce.iss.net/xforce/xfdb/36740",Assigned (20070919),"None (candidate not yet proposed)",
136| [CVE-2007-5030,Candidate,"Multiple integer overflows in Dibbler 0.6.0 allow remote attackers to cause a denial of service (daemon crash) via packets containing options with large lengths, which trigger attempts at excessive memory allocation, as demonstrated by (1) the TSrvMsg constructor in SrvMessages/SrvMsg.cpp] the (2) TClntMsg, (3) TClntOptIAAddress, (4) TClntOptIAPrefix, (5) TOptVendorSpecInfo, and (6) TOptOptionRequest constructors
137| [CVE-2007-5146,Candidate,"Multiple PHP remote file inclusion vulnerabilities in dedi-group Der Dirigent 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the dedi_path parameter to (1) inc.generate_code.php, (2) fnc.type_forms.php, or (3) fnc.type.php in backend/inc/, or (4) frontend.php or (5) backend.php in projekt01/cms/inc/] or (6) the this_dir parameter to backend/inc/class.filemanager.php. NOTE: vectors 4 and 5 are disputed by CVE because PHP encounters a fatal function-call error on a direct request for the file, before reaching the include statement.","MISC:http://arfis.wordpress.com/2007/09/14/rfi-02-der-dirigent/ | OSVDB:45535 | URL:http://osvdb.org/45535 | OSVDB:45536 | URL:http://osvdb.org/45536 | OSVDB:45537 | URL:http://osvdb.org/45537 | OSVDB:45538 | URL:http://osvdb.org/45538 | OSVDB:45539 | URL:http://osvdb.org/45539 | OSVDB:45540 | URL:http://osvdb.org/45540",Assigned (20070930),"None (candidate not yet proposed)",
138| [CVE-2007-5362,Candidate,"Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) credits.html.php, (2) info.html.php, (3) media.divs.php, (4) media.divs.js.php, (5) purchase.html.php, or (6) support.html.php in includes/. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. NOTE: vector 3 may be the same as CVE-2007-2043.2.","BID:25960 | URL:http://www.securityfocus.com/bid/25960 | OSVDB:38586 | URL:http://osvdb.org/38586 | OSVDB:38587 | URL:http://osvdb.org/38587 | OSVDB:38588 | URL:http://osvdb.org/38588 | XF:mosmedialite451-mosconfig-file-include(37015) | URL:http://xforce.iss.net/xforce/xfdb/37015",Assigned (20071010),"None (candidate not yet proposed)",
139| [CVE-2007-5402,Candidate,"Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to editrequestenduser.asp] and allow remote authenticated users to execute arbitrary SQL commands via (2) the oldpassword parameter to writepwdenduser.asp, and the sys_request_id parameter to (3) changerequeststatus.asp, (4) editrequestuser.asp, (5) requestcommentsuser.asp, and (6) useractions.asp, different vectors than CVE-2004-2551.","MISC:http://secunia.com/secunia_research/2007-94/advisory/ | BID:27187 | URL:http://www.securityfocus.com/bid/27187 | SECUNIA:27699 | URL:http://secunia.com/advisories/27699 | XF:helpbox-sysrequestid-sql-injection(39539) | URL:http://xforce.iss.net/xforce/xfdb/39539 | XF:helpbox-writepwdenduser-sql-injection(39538) | URL:http://xforce.iss.net/xforce/xfdb/39538",Assigned (20071012),"None (candidate not yet proposed)",
140| [CVE-2007-5407,Candidate,"Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) jcs.function.php] (2) add.php, (3) history.php, and (4) register.php, in view/
141| [CVE-2007-5589,Candidate,"Muliple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via certain input available in (1) PHP_SELF in (a) server_status.php, and (b) grab_globals.lib.php, (c) display_change_password.lib.php, and (d) common.lib.php in libraries/] and certain input available in PHP_SELF and (2) PATH_INFO in libraries/common.inc.php. NOTE: there might also be other vectors related to (3) REQUEST_URI.","MISC:http://www.digitrustgroup.com/advisories/TDG-advisory071015a.html | CONFIRM:http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_1/phpMyAdmin/ChangeLog?r1=10796&r2=10795&pathrev=10796 | CONFIRM:http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=10796 | CONFIRM:http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-6 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=333661 | DEBIAN:DSA-1403 | URL:http://www.debian.org/security/2007/dsa-1403 | FEDORA:FEDORA-2007-2738 | URL:https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00040.html | MANDRIVA:MDKSA-2007:199 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:199 | SUSE:SUSE-SR:2008:006 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html | BID:26301 | URL:http://www.securityfocus.com/bid/26301 | VUPEN:ADV-2007-3535 | URL:http://www.vupen.com/english/advisories/2007/3535 | OSVDB:37939 | URL:http://osvdb.org/37939 | SECUNIA:27246 | URL:http://secunia.com/advisories/27246 | SECUNIA:27506 | URL:http://secunia.com/advisories/27506 | SECUNIA:27595 | URL:http://secunia.com/advisories/27595 | SECUNIA:29323 | URL:http://secunia.com/advisories/29323 | XF:phpmyadmin-serverstatus-xss(37292) | URL:http://xforce.iss.net/xforce/xfdb/37292",Assigned (20071019),"None (candidate not yet proposed)",
142| [CVE-2007-5631,Candidate,"Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the current_blockmodule_path parameter to (1) AudiosMediaGalleryModule/AudiosMediaGalleryModule.php, (2) ImagesMediaGalleryModule/ImagesMediaGalleryModule.php, (3) MembersFacewallModule/MembersFacewallModule.php, (4) NewestGroupsModule/NewestGroupsModule.php, (5) UploadMediaModule/UploadMediaModule.php, and (6) VideosMediaGalleryModule/VideosMediaGalleryModule.php in BetaBlockModules/] and (7) the path_prefix parameter to several components.","BUGTRAQ:20071111 PeopleAggregatory security advisory - re CVE-2007-5631 | URL:http://www.securityfocus.com/archive/1/archive/1/483571/100/0/threaded | MILW0RM:4551 | URL:http://www.milw0rm.com/exploits/4551 | CONFIRM:http://www.myelin.co.nz/post/2007/11/12/#200711121 | BID:26147 | URL:http://www.securityfocus.com/bid/26147 | OSVDB:45495 | URL:http://osvdb.org/45495 | OSVDB:45496 | URL:http://osvdb.org/45496 | OSVDB:45497 | URL:http://osvdb.org/45497 | OSVDB:45498 | URL:http://osvdb.org/45498 | OSVDB:45499 | URL:http://osvdb.org/45499 | OSVDB:45500 | URL:http://osvdb.org/45500 | OSVDB:45501 | URL:http://osvdb.org/45501 | XF:peopleaggregator-pathprefix-file-include(37349) | URL:http://xforce.iss.net/xforce/xfdb/37349",Assigned (20071023),"None (candidate not yet proposed)",
143| [CVE-2007-6188,Candidate,"Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) languages_n.php, (2) languages_f.php, or (3) languages.php in inc/] and (4) allow remote attackers to read arbitrary local files via a .. (dot dot) in the uri parameter to frames/nogui/sc_download.php.","MILW0RM:4674 | URL:http://www.milw0rm.com/exploits/4674 | BID:26631 | URL:http://www.securityfocus.com/bid/26631 | BID:26632 | URL:http://www.securityfocus.com/bid/26632 | OSVDB:42450 | URL:http://osvdb.org/42450 | OSVDB:42451 | URL:http://osvdb.org/42451 | OSVDB:42452 | URL:http://osvdb.org/42452 | OSVDB:42453 | URL:http://osvdb.org/42453 | SECUNIA:27866 | URL:http://secunia.com/advisories/27866 | XF:tumusika-language-directory-traversal(38720) | URL:http://xforce.iss.net/xforce/xfdb/38720 | XF:tumusika-scdownload-directory-traversal(38719) | URL:http://xforce.iss.net/xforce/xfdb/38719",Assigned (20071129),"None (candidate not yet proposed)",
144| [CVE-2007-6191,Candidate,"Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PM_INCPHP] parameter to (1) incphp/globals.php or (2) plugins/export/mc_table.php. NOTE: it could be argued that this vulnerability is caused by a problem in PHP and the proper fix should be in PHP] if so, then this should not be treated as a vulnerability in p.mapper.","MISC:http://www.packetstormsecurity.org/0711-exploits/pmapper-rfi.txt | BID:26614 | URL:http://www.securityfocus.com/bid/26614 | SECUNIA:27876 | URL:http://secunia.com/advisories/27876 | XF:pmapper-sessionpmincphp-file-include(38732) | URL:http://xforce.iss.net/xforce/xfdb/38732",Assigned (20071129),"None (candidate not yet proposed)",
145| [CVE-2007-6218,Candidate,"Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) install_module.php and (b) uninstall_module.php in upload/xax/admin/modules/, (c) upload/xax/admin/patch/index.php, and (d) install_module.php and (e) uninstall_module.php in upload/xax/ossigeno/admin/] and the (2) ossigeno parameter to (f) ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php, different vectors than CVE-2007-5234.","MISC:http://www.packetstormsecurity.org/0711-exploits/ossigeno22-rfi.txt | BID:26654 | URL:http://www.securityfocus.com/bid/26654 | OSVDB:44312 | URL:http://osvdb.org/44312 | OSVDB:44313 | URL:http://osvdb.org/44313 | OSVDB:44314 | URL:http://osvdb.org/44314 | OSVDB:44315 | URL:http://osvdb.org/44315 | OSVDB:44316 | URL:http://osvdb.org/44316 | OSVDB:44317 | URL:http://osvdb.org/44317",Assigned (20071204),"None (candidate not yet proposed)",
146| [CVE-2007-6277,Candidate,"Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via large (1) Metadata Block Size, (2) VORBIS Comment String Size, (3) Picture Metadata MIME-TYPE Size, (4) Picture Description Size, (5) Picture Data Length, (6) Padding Length, and (7) PICTURE Metadata width and height values in a .FLAC file, which result in a heap-based overflow] and large (8) VORBIS Comment String Size Length, (9) Picture MIME-Type, (10) Picture MIME-Type URL, and (11) Picture Description Length values in a .FLAC file, which result in a stack-based overflow. NOTE: some of these issues may overlap CVE-2007-4619.","EEYE:AD20071115 | URL:http://research.eeye.com/html/advisories/published/AD20071115.html | BUGTRAQ:20071115 EEYE: Multiple Vulnerabilities In .FLAC File Format and Various Media Applications | URL:http://www.securityfocus.com/archive/1/archive/1/483765/100/200/threaded | DEBIAN:DSA-1469 | URL:http://www.debian.org/security/2008/dsa-1469 | CERT-VN:VU#544656 | URL:http://www.kb.cert.org/vuls/id/544656 | OVAL:oval:org.mitre.oval:def:10435 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10435 | SECTRACK:1018974 | URL:http://www.securitytracker.com/id?1018974 | SECUNIA:28548 | URL:http://secunia.com/advisories/28548 | SREASON:3423 | URL:http://securityreason.com/securityalert/3423",Assigned (20071207),"None (candidate not yet proposed)",
147| [CVE-2007-6319,Candidate,"Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote attackers to (1) gain list administrator privileges or (2) access arbitrary mailing lists via unknown vectors related to modification of client-side information] and (3) allow remote authenticated administrators to modify other account data by creating ""new accounts that collide with existing accounts.""","BUGTRAQ:20080218 SYMSA-2008-001: Lyris ListManager - Multiple Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/488343/100/0/threaded | BID:26792 | URL:http://www.securityfocus.com/bid/26792 | VUPEN:ADV-2008-0618 | URL:http://www.vupen.com/english/advisories/2008/0618 | SECTRACK:1019436 | URL:http://securitytracker.com/id?1019436 | SECUNIA:29019 | URL:http://secunia.com/advisories/29019 | SREASON:3671 | URL:http://securityreason.com/securityalert/3671",Assigned (20071211),"None (candidate not yet proposed)",
148| [CVE-2007-6365,Candidate,"Cross-site scripting (XSS) vulnerability in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 allows remote attackers to inject arbitrary web script or HTML via the month parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. NOTE: the day and year vectors are covered by CVE-2007-6274.","SECUNIA:26945 | URL:http://secunia.com/advisories/26945",Assigned (20071214),"None (candidate not yet proposed)",
149| [CVE-2007-6407,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Provisioning Manager Express allow remote attackers to inject arbitrary web script or HTML via the (1) ""assess modification,"" (2) user-id, and other unspecified fields to the /tpmx URI] or (3) involving unspecified vectors related to ""error processing.""","BUGTRAQ:20071205 [ELEYTT] Public Advisory 05-12-2007 | URL:http://www.securityfocus.com/archive/1/archive/1/484607/100/0/threaded | SECTRACK:1019045 | URL:http://securitytracker.com/id?1019045 | SREASON:3458 | URL:http://securityreason.com/securityalert/3458 | XF:provisioningmanager-multiple-xss(38864) | URL:http://xforce.iss.net/xforce/xfdb/38864",Assigned (20071217),"None (candidate not yet proposed)",
150| [CVE-2007-6461,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrary web script or HTML via (1) the query string in an index action, related to the savesearch JavaScript function] and (2) the details parameter in a details action, related to the History tab and the getHistory JavaScript function.","CONFIRM:http://flyspray.org/fsa:2 | OSVDB:39256 | URL:http://osvdb.org/39256 | OSVDB:39257 | URL:http://osvdb.org/39257 | SECUNIA:28106 | URL:http://secunia.com/advisories/28106",Assigned (20071219),"None (candidate not yet proposed)",
151| [CVE-2007-6502,Candidate,"Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames] and (2) certain XML HTTP requests to hosting/css.asp using Microsoft.XMLHTTP or MSXML2.XMLHTTP objects, which trigger a response with the setup directory pathname in the HTML source
152| [CVE-2007-6584,Candidate,"Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to pages/download/default/ops/search.php] or the admin_theme_dir parameter to (3) download.php, (4) forum.php, or (5) news.php in admin/ops/reports/ops/. NOTE: it was later reported that 1.4.2 beta and earlier are also affected for vector 1.","MILW0RM:4765 | URL:http://www.milw0rm.com/exploits/4765 | MILW0RM:5434 | URL:http://www.milw0rm.com/exploits/5434 | BID:28753 | URL:http://www.securityfocus.com/bid/28753 | OSVDB:41280 | URL:http://osvdb.org/41280 | OSVDB:41281 | URL:http://osvdb.org/41281 | OSVDB:41282 | URL:http://osvdb.org/41282 | OSVDB:41283 | URL:http://osvdb.org/41283 | OSVDB:41284 | URL:http://osvdb.org/41284 | SECUNIA:29810 | URL:http://secunia.com/advisories/29810",Assigned (20071228),"None (candidate not yet proposed)",
153| [CVE-2007-6755,Candidate,"The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain ""skeleton key"" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG] future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.","MISC:http://arstechnica.com/security/2013/09/stop-using-nsa-influence-code-in-our-product-rsa-tells-customers/ | MISC:http://blog.cryptographyengineering.com/2013/09/rsa-warns-developers-against-its-own.html | MISC:http://blog.cryptographyengineering.com/2013/09/the-many-flaws-of-dualecdrbg.html | MISC:http://rump2007.cr.yp.to/15-shumow.pdf | MISC:http://stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2-332655/ | MISC:http://threatpost.com/in-wake-of-latest-crypto-revelations-everything-is-suspect | MISC:https://www.schneier.com/blog/archives/2007/11/the_strange_sto.html",Assigned (20131011),"None (candidate not yet proposed)",
154| [CVE-2008-0091,Candidate,"Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter.","MILW0RM:4828 | URL:http://www.milw0rm.com/exploits/4828 | VIM:20080104 true: AGENCY4NET WEBFTP directory traversal] deletion possible | URL:http://www.attrition.org/pipermail/vim/2008-January/001865.html | BID:27092 | URL:http://www.securityfocus.com/bid/27092 | VUPEN:ADV-2008-0051 | URL:http://www.vupen.com/english/advisories/2008/0051 | SECUNIA:28309 | URL:http://secunia.com/advisories/28309 | XF:agency4net-download2-directory-traversal(39343) | URL:http://xforce.iss.net/xforce/xfdb/39343",Assigned (20080103),"None (candidate not yet proposed)",
155| [CVE-2008-0265,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2) list_pktfilter.jsp, (3) list_ltm.jsp, (4) resources_audit.jsp, and (5) list_asm.jsp in tmui/Control/jspmap/tmui/system/log/] and (6) list.jsp in certain directories.","BUGTRAQ:20080114 F5 BIG-IP Web Management List Search XSS | URL:http://www.securityfocus.com/archive/1/archive/1/486217/100/0/threaded | BID:27272 | URL:http://www.securityfocus.com/bid/27272 | VUPEN:ADV-2008-0181 | URL:http://www.vupen.com/english/advisories/2008/0181 | SECTRACK:1019190 | URL:http://www.securitytracker.com/id?1019190 | SECUNIA:28505 | URL:http://secunia.com/advisories/28505 | SREASON:3545 | URL:http://securityreason.com/securityalert/3545 | XF:f5bigip-searchstring-xss(39632) | URL:http://xforce.iss.net/xforce/xfdb/39632",Assigned (20080115),"None (candidate not yet proposed)",
156| [CVE-2008-0267,Candidate,"Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php] and allow remote authenticated administrators to execute arbitrary SQL commands via the (4) msg and (5) password parameters to admin.php.","BUGTRAQ:20080106 eTicket 1.5.5.2 Multiple Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded | BID:27173 | URL:http://www.securityfocus.com/bid/27173 | SECUNIA:28331 | URL:http://secunia.com/advisories/28331 | SREASON:3542 | URL:http://securityreason.com/securityalert/3542 | XF:eticket-search-sql-injection(39489) | URL:http://xforce.iss.net/xforce/xfdb/39489 | XF:eticket-admin-sql-injection(39487) | URL:http://xforce.iss.net/xforce/xfdb/39487",Assigned (20080115),"None (candidate not yet proposed)",
157| [CVE-2008-0364,Candidate,"Buffer overflow in (1) BitTorrent 6.0 and earlier] and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series
158| [CVE-2008-0405,Candidate,"Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI] and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a ""/?%0a"" sequence followed by the data.","BUGTRAQ:20080123 Syhunt: HFS (HTTP File Server) Log Arbitrary File/Directory Manipulation and Denial-of-Service Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/486873/100/0/threaded | MISC:http://www.rejetto.com/hfs/?f=wn | MISC:http://www.syhunt.com/advisories/hfs-1-log.txt | MISC:http://www.syhunt.com/advisories/hfshack.txt | BID:27423 | URL:http://www.securityfocus.com/bid/27423 | SECUNIA:28631 | URL:http://secunia.com/advisories/28631 | SREASON:3581 | URL:http://securityreason.com/securityalert/3581 | XF:hfs-unspecified-command-execution(39873) | URL:http://xforce.iss.net/xforce/xfdb/39873",Assigned (20080122),"None (candidate not yet proposed)",
159| [CVE-2008-0420,Candidate,"modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element] or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.","BUGTRAQ:20080216 [HISPASEC] FireFox 2.0.0.11 and Opera 9.50 beta Remote Memory Information Leak, FireFox 2.0.0.11 Remote Denial of Service | URL:http://www.securityfocus.com/archive/1/archive/1/488264/100/0/threaded | CONFIRM:http://www.mozilla.org/security/announce/2008/mfsa2008-07.html | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=408076 | CONFIRM:http://browser.netscape.com/releasenotes/ | FEDORA:FEDORA-2008-2060 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html | FEDORA:FEDORA-2008-2118 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html | GENTOO:GLSA-200805-18 | URL:http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml | MANDRIVA:MDVSA-2008:048 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:048 | SUNALERT:238492 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1 | UBUNTU:USN-576-1 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-576-1 | UBUNTU:USN-582-1 | URL:http://www.ubuntu.com/usn/usn-582-1 | UBUNTU:USN-582-2 | URL:http://www.ubuntu.com/usn/usn-582-2 | BID:27826 | URL:http://www.securityfocus.com/bid/27826 | OVAL:oval:org.mitre.oval:def:10119 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10119 | VUPEN:ADV-2008-0627 | URL:http://www.vupen.com/english/advisories/2008/0627/references | VUPEN:ADV-2008-1793 | URL:http://www.vupen.com/english/advisories/2008/1793/references | SECTRACK:1019434 | URL:http://securitytracker.com/id?1019434 | SECUNIA:28839 | URL:http://secunia.com/advisories/28839 | SECUNIA:29049 | URL:http://secunia.com/advisories/29049 | SECUNIA:28758 | URL:http://secunia.com/advisories/28758 | SECUNIA:29167 | URL:http://secunia.com/advisories/29167 | SECUNIA:29098 | URL:http://secunia.com/advisories/29098 | SECUNIA:30327 | URL:http://secunia.com/advisories/30327 | SECUNIA:30620 | URL:http://secunia.com/advisories/30620 | XF:firefox-bmp-information-disclosure(40491) | URL:http://xforce.iss.net/xforce/xfdb/40491 | XF:firefox-bmp-dos(40606) | URL:http://xforce.iss.net/xforce/xfdb/40606",Assigned (20080123),"None (candidate not yet proposed)",
160| [CVE-2008-0508,Candidate,"Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting.","BUGTRAQ:20080122 XSRF under Deanâ] ??s Permalinks Migration 1.0 | URL:http://www.securityfocus.com/archive/1/archive/1/486840/100/0/threaded | MISC:http://g30rg3x.com/wp-files/dpm_11gx.zip | MISC:http://g30rg3x.com/xsrf-bajo-deans-permalinks-migration-10 | MISC:http://packetstorm.linuxsecurity.com/0801-advisories/deans-xsrf.txt | VUPEN:ADV-2008-0281 | URL:http://www.vupen.com/english/advisories/2008/0281 | SECUNIA:28593 | URL:http://secunia.com/advisories/28593 | SREASON:3595 | URL:http://securityreason.com/securityalert/3595 | XF:permalinks-deanpmconfig-csrf(39845) | URL:http://xforce.iss.net/xforce/xfdb/39845",Assigned (20080131),"None (candidate not yet proposed)",
161| [CVE-2008-0509,Candidate,"Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c] or (2) piox25remote, related to piox25remote.sh.","AIXAPAR:IZ13739 | URL:http://www-1.ibm.com/support/docview.wss?uid=isg1IZ13739 | BID:27510 | URL:http://www.securityfocus.com/bid/27510 | OVAL:oval:org.mitre.oval:def:5796 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5796 | VUPEN:ADV-2008-0324 | URL:http://www.vupen.com/english/advisories/2008/0324 | SECUNIA:28600 | URL:http://secunia.com/advisories/28600",Assigned (20080131),"None (candidate not yet proposed)",
162| [CVE-2008-0545,Candidate,"Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/] and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.","MILW0RM:4991 | URL:http://www.milw0rm.com/exploits/4991 | BID:27466 | URL:http://www.securityfocus.com/bid/27466 | VUPEN:ADV-2008-0347 | URL:http://www.vupen.com/english/advisories/2008/0347 | XF:bubblinglibrary-page-uri-file-include(39969) | URL:http://xforce.iss.net/xforce/xfdb/39969",Assigned (20080201),"None (candidate not yet proposed)",
163| [CVE-2008-0586,Candidate,"Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldeletepv, (3) putlvodm, (4) lvaryoffvg, and (5) lvgenminor programs in bos.rte.lvm] and the (6) tellclvmd program in bos.clvm.enh.","CONFIRM:http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4068 | CONFIRM:http://aix.software.ibm.com/aix/efixes/security/lvm_advisory.asc | AIXAPAR:IY98331 | URL:http://www.ibm.com/support/docview.wss?uid=isg1IY98331 | AIXAPAR:IY98340 | URL:http://www.ibm.com/support/docview.wss?uid=isg1IY98340 | AIXAPAR:IY99537 | URL:http://www.ibm.com/support/docview.wss?uid=isg1IY99537 | AIXAPAR:IZ00559 | URL:http://www.ibm.com/support/docview.wss?uid=isg1IZ00559 | AIXAPAR:IZ10828 | URL:http://www.ibm.com/support/docview.wss?uid=isg1IZ10828 | AIXAPAR:IY98448 | URL:http://www-1.ibm.com/support/docview.wss?uid=isg1IY98448 | AIXAPAR:IY98450 | URL:http://www-1.ibm.com/support/docview.wss?uid=isg1IY98450 | BID:27431 | URL:http://www.securityfocus.com/bid/27431 | OSVDB:40427 | URL:http://osvdb.org/40427 | OSVDB:40428 | URL:http://osvdb.org/40428 | OSVDB:40429 | URL:http://osvdb.org/40429 | OVAL:oval:org.mitre.oval:def:5704 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5704 | VUPEN:ADV-2008-0261 | URL:http://www.vupen.com/english/advisories/2008/0261 | SECUNIA:28609 | URL:http://secunia.com/advisories/28609 | XF:aix-lvm-commands-bo(39907) | URL:http://xforce.iss.net/xforce/xfdb/39907",Assigned (20080204),"None (candidate not yet proposed)",
164| [CVE-2008-0742,Candidate,"Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php, and (f) users.inc.php in pnadmin/] and (2) the page parameter to (g) pnadmin/index.php. NOTE: vector 2 is only exploitable by administrators.","BUGTRAQ:20080208 [DSECRG-08-014] Multiple LFI in PowerNews (Newsscript) 2.5.6 | URL:http://www.securityfocus.com/archive/1/archive/1/487773/100/0/threaded | MILW0RM:5082 | URL:http://www.milw0rm.com/exploits/5082 | BID:27688 | URL:http://www.securityfocus.com/bid/27688 | SREASON:3647 | URL:http://securityreason.com/securityalert/3647",Assigned (20080212),"None (candidate not yet proposed)",
165| [CVE-2008-0828,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) attributes such as style and onmouseover in (a) forum post or (b) mail] or (2) the website field of the profile.","BUGTRAQ:20080217 ATutor <= 1.5.5 Cross Site Scripting | URL:http://www.securityfocus.com/archive/1/archive/1/488293/100/0/threaded | BID:27855 | URL:http://www.securityfocus.com/bid/27855 | SECUNIA:29015 | URL:http://secunia.com/advisories/29015 | SREASON:3670 | URL:http://securityreason.com/securityalert/3670",Assigned (20080219),"None (candidate not yet proposed)",
166| [CVE-2008-1098,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) certain input processed by formatter/text_gedit.py (aka the gui editor formatter)] (2) a page name, which triggers an injection in PageEditor.py when the page is successfully deleted by a victim in a DeletePage action
167| [CVE-2008-1212,Candidate,"Cross-site scripting (XSS) vulnerability in set_permissions.php in Podcast Generator 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the scriptlang parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:28106 | URL:http://www.securityfocus.com/bid/28106 | XF:podcastgenerator-setpermissions-xss(41130) | URL:http://xforce.iss.net/xforce/xfdb/41130",Assigned (20080307),"None (candidate not yet proposed)",
168| [CVE-2008-1311,Candidate,"The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of service (daemon hang) by uploading a file named (1) '|' (pipe), (2) '""' (quotation mark), or (3) ""<>"" (less than, greater than)] or (4) a file with a long name. NOTE: the issue for vector 4 might exist because of an incomplete fix for CVE-2008-1312.","BUGTRAQ:20080310 Denial of Service in PacketTrap TFTP server 2.0.3901.0 | URL:http://www.securityfocus.com/archive/1/archive/1/489355/100/0/threaded | MISC:http://aluigi.altervista.org/adv/packettrash-adv.txt | MISC:http://aluigi.org/testz/tftpx.zip | BID:28187 | URL:http://www.securityfocus.com/bid/28187 | VUPEN:ADV-2008-0811 | URL:http://www.vupen.com/english/advisories/2008/0811/references | SECUNIA:29308 | URL:http://secunia.com/advisories/29308 | SREASON:3734 | URL:http://securityreason.com/securityalert/3734 | XF:pt360-tftpserver-filename-dos(41073) | URL:http://xforce.iss.net/xforce/xfdb/41073",Assigned (20080312),"None (candidate not yet proposed)",
169| [CVE-2008-1313,Candidate,"Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) post_id, (2) post_category_id, (3) post_year_month, and (4) static_page_id parameters] and unspecified other vectors.","MILW0RM:5234 | URL:http://www.milw0rm.com/exploits/5234 | BID:28203 | URL:http://www.securityfocus.com/bid/28203 | SECUNIA:29338 | URL:http://secunia.com/advisories/29338 | XF:bloo-index-sql-injection(41141) | URL:http://xforce.iss.net/xforce/xfdb/41141",Assigned (20080312),"None (candidate not yet proposed)",
170| [CVE-2008-1341,Candidate,"SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","MISC:http://support.storefront.net/Updates/60sp8/default.asp | BID:28234 | URL:http://www.securityfocus.com/bid/28234 | SECUNIA:29326 | URL:http://secunia.com/advisories/29326",Assigned (20080317),"None (candidate not yet proposed)",
171| [CVE-2008-1355,Candidate,"Cross-site scripting (XSS) vulnerability in index.php in Jeebles Technology Jeebles Directory 2.9.60 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","MISC:http://downloads.securityfocus.com/vulnerabilities/exploits/28221.html | BID:28221 | URL:http://www.securityfocus.com/bid/28221 | XF:jeeblesdirectory-path-xss(41183) | URL:http://xforce.iss.net/xforce/xfdb/41183",Assigned (20080317),"None (candidate not yet proposed)",
172| [CVE-2008-1508,Candidate,"SQL injection vulnerability in EfesTech E-Kont\xF6r and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.","BUGTRAQ:20080323 EfesTech E-Kontö] r (id) Remote SQL INJECTION | URL:http://www.securityfocus.com/archive/1/archive/1/489989/100/0/threaded | BID:28412 | URL:http://www.securityfocus.com/bid/28412 | SECUNIA:29499 | URL:http://secunia.com/advisories/29499 | SREASON:3776 | URL:http://securityreason.com/securityalert/3776 | XF:ekontor-id-sql-injection(41419) | URL:http://xforce.iss.net/xforce/xfdb/41419",Assigned (20080325),"None (candidate not yet proposed)",
173| [CVE-2008-1736,Candidate,"Comodo Firewall Pro before 3.0 does not properly validate certain parameters to hooked System Service Descriptor Table (SSDT) functions, which allows local users to cause a denial of service (system crash) via (1) a crafted OBJECT_ATTRIBUTES structure in a call to the NtDeleteFile function, which leads to improper validation of a ZwQueryObject result] and unspecified calls to the (2) NtCreateFile and (3) NtSetThreadContext functions, different vectors than CVE-2007-0709.","BUGTRAQ:20080428 CORE-2008-0320 - Insufficient argument validation of hooked SSDT functions on multiple Antivirus and Firewalls | URL:http://www.securityfocus.com/archive/1/archive/1/491405/100/0/threaded | MISC:http://www.coresecurity.com/?action=item&id=2249 | MISC:http://www.personalfirewall.comodo.com/release_notes.html | BID:28742 | URL:http://www.securityfocus.com/bid/28742 | VUPEN:ADV-2008-1383 | URL:http://www.vupen.com/english/advisories/2008/1383 | SECTRACK:1019944 | URL:http://securitytracker.com/id?1019944 | SECUNIA:30006 | URL:http://secunia.com/advisories/30006 | SREASON:3838 | URL:http://securityreason.com/securityalert/3838 | XF:comodo-ssdt-dos(42082) | URL:http://xforce.iss.net/xforce/xfdb/42082",Assigned (20080411),"None (candidate not yet proposed)",
174| [CVE-2008-1769,Candidate,"VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.","MISC:http://bugs.gentoo.org/show_bug.cgi?id=214627#c3 | MISC:http://git.videolan.org/gitweb.cgi/vlc.git/?a=commit] h=cf489d7bff3c1b36b2d5501ecf21129c78104d98 | CONFIRM:http://www.videolan.org/developers/vlc/NEWS | CONFIRM:http://www.videolan.org/security/sa0803.php | CONFIRM:http://wiki.videolan.org/Changelog/0.8.6f | GENTOO:GLSA-200804-25 | URL:http://security.gentoo.org/glsa/glsa-200804-25.xml | BID:28904 | URL:http://www.securityfocus.com/bid/28904 | OVAL:oval:org.mitre.oval:def:14445 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14445 | SECUNIA:29800 | URL:http://secunia.com/advisories/29800 | SECUNIA:29503 | URL:http://secunia.com/advisories/29503 | VUPEN:ADV-2008-0985 | URL:http://www.vupen.com/english/advisories/2008/0985",Assigned (20080412),"None (candidate not yet proposed)",
175| [CVE-2008-1892,Candidate,"Cross-site scripting (XSS) vulnerability in bs_auth.php in Blogator-script 0.95 and 1.01 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:28810 | URL:http://www.securityfocus.com/bid/28810 | SECUNIA:29684 | URL:http://secunia.com/advisories/29684 | XF:blogatorscript-bsauth-xss(41930) | URL:http://xforce.iss.net/xforce/xfdb/41930",Assigned (20080418),"None (candidate not yet proposed)",
176| [CVE-2008-2034,Candidate,"SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:28975 | URL:http://www.securityfocus.com/bid/28975 | SECUNIA:29876 | URL:http://secunia.com/advisories/29876 | XF:downloadmonitor-id-sql-injection(42094) | URL:http://xforce.iss.net/xforce/xfdb/42094",Assigned (20080430),"None (candidate not yet proposed)",
177| [CVE-2008-2520,Candidate,"Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[_BIGACE][DIR][addon] parameter to (a) addon/smarty/plugins/function.captcha.php and (b) system/classes/sql/AdoDBConnection.php] and the (2) GLOBALS[_BIGACE][DIR][admin] parameter to (c) item_information.php and (d) jstree.php in system/application/util/, and (e) system/admin/plugins/menu/menuTree/plugin.php, different vectors than CVE-2006-4423.","MILW0RM:5596 | URL:http://www.milw0rm.com/exploits/5596 | BID:29157 | URL:http://www.securityfocus.com/bid/29157 | SECUNIA:30183 | URL:http://secunia.com/advisories/30183 | XF:bigace-multiple-file-include(42343) | URL:http://xforce.iss.net/xforce/xfdb/42343",Assigned (20080603),"None (candidate not yet proposed)",
178| [CVE-2008-2725,Candidate,"Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22] and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the ""REALLOC_N"" variant, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2664. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.","BUGTRAQ:20080626 rPSA-2008-0206-1 ruby | URL:http://www.securityfocus.com/archive/1/archive/1/493688/100/0/threaded | MISC:http://blog.phusion.nl/2008/06/23/ruby-186-p230187-broke-your-app-ruby-enterprise-edition-to-the-rescue/ | MISC:http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilities | MISC:http://www.matasano.com/log/1070/updates-on-drew-yaos-terrible-ruby-vulnerabilities/ | MISC:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2727 | MISC:http://www.ruby-forum.com/topic/157034 | MISC:http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.html | MISC:http://www.zedshaw.com/rants/the_big_ruby_vulnerabilities.html | MLIST:[fedora-security-commits] 20080620 fedora-security/audit f10, 1.7, 1.8 f8, 1.225, 1.226 f9, 1.215, 1.216 | URL:http://www.redhat.com/archives/fedora-security-commits/2008-June/msg00005.html | CONFIRM:http://support.apple.com/kb/HT2163 | CONFIRM:http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/ | CONFIRM:https://bugs.launchpad.net/ubuntu/+source/ruby1.8/+bug/241657 | CONFIRM:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0206 | CONFIRM:https://issues.rpath.com/browse/RPL-2626 | APPLE:APPLE-SA-2008-06-30 | URL:http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html | DEBIAN:DSA-1612 | URL:http://www.debian.org/security/2008/dsa-1612 | DEBIAN:DSA-1618 | URL:http://www.debian.org/security/2008/dsa-1618 | FEDORA:FEDORA-2008-5649 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.html | GENTOO:GLSA-200812-17 | URL:http://security.gentoo.org/glsa/glsa-200812-17.xml | MANDRIVA:MDVSA-2008:140 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:140 | MANDRIVA:MDVSA-2008:141 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:141 | MANDRIVA:MDVSA-2008:142 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:142 | REDHAT:RHSA-2008:0561 | URL:http://www.redhat.com/support/errata/RHSA-2008-0561.html | SLACKWARE:SSA:2008-179-01 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562 | SUSE:SUSE-SR:2008:017 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html | UBUNTU:USN-621-1 | URL:http://www.ubuntu.com/usn/usn-621-1 | BID:29903 | URL:http://www.securityfocus.com/bid/29903 | OVAL:oval:org.mitre.oval:def:9606 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9606 | VUPEN:ADV-2008-1907 | URL:http://www.vupen.com/english/advisories/2008/1907/references | VUPEN:ADV-2008-1981 | URL:http://www.vupen.com/english/advisories/2008/1981/references | SECTRACK:1020347 | URL:http://www.securitytracker.com/id?1020347 | SECUNIA:30831 | URL:http://secunia.com/advisories/30831 | SECUNIA:30802 | URL:http://secunia.com/advisories/30802 | SECUNIA:31062 | URL:http://secunia.com/advisories/31062 | SECUNIA:31090 | URL:http://secunia.com/advisories/31090 | SECUNIA:31181 | URL:http://secunia.com/advisories/31181 | SECUNIA:31256 | URL:http://secunia.com/advisories/31256 | SECUNIA:31687 | URL:http://secunia.com/advisories/31687 | SECUNIA:30867 | URL:http://secunia.com/advisories/30867 | SECUNIA:30875 | URL:http://secunia.com/advisories/30875 | SECUNIA:30894 | URL:http://secunia.com/advisories/30894 | SECUNIA:33178 | URL:http://secunia.com/advisories/33178 | XF:ruby-rbarysplice-code-execution(43350) | URL:http://xforce.iss.net/xforce/xfdb/43350",Assigned (20080616),"None (candidate not yet proposed)",
179| [CVE-2008-2726,Candidate,"Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2] and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the ""beg + rlen"" issue. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.","BUGTRAQ:20080626 rPSA-2008-0206-1 ruby | URL:http://www.securityfocus.com/archive/1/archive/1/493688/100/0/threaded | MISC:http://blog.phusion.nl/2008/06/23/ruby-186-p230187-broke-your-app-ruby-enterprise-edition-to-the-rescue/ | MISC:http://weblog.rubyonrails.org/2008/6/21/multiple-ruby-security-vulnerabilities | MISC:http://www.matasano.com/log/1070/updates-on-drew-yaos-terrible-ruby-vulnerabilities/ | MISC:http://www.ruby-forum.com/topic/157034 | MISC:http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.html | MISC:http://www.zedshaw.com/rants/the_big_ruby_vulnerabilities.html | MLIST:[fedora-security-commits] 20080620 fedora-security/audit f10, 1.7, 1.8 f8, 1.225, 1.226 f9, 1.215, 1.216 | URL:http://www.redhat.com/archives/fedora-security-commits/2008-June/msg00005.html | CONFIRM:https://bugs.launchpad.net/ubuntu/+source/ruby1.8/+bug/241657 | CONFIRM:http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=17460 | CONFIRM:http://www.ruby-lang.org/en/news/2008/06/20/arbitrary-code-execution-vulnerabilities/ | CONFIRM:http://support.apple.com/kb/HT2163 | CONFIRM:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0206 | CONFIRM:https://issues.rpath.com/browse/RPL-2626 | APPLE:APPLE-SA-2008-06-30 | URL:http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html | DEBIAN:DSA-1612 | URL:http://www.debian.org/security/2008/dsa-1612 | DEBIAN:DSA-1618 | URL:http://www.debian.org/security/2008/dsa-1618 | FEDORA:FEDORA-2008-5649 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00937.html | GENTOO:GLSA-200812-17 | URL:http://security.gentoo.org/glsa/glsa-200812-17.xml | MANDRIVA:MDVSA-2008:140 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:140 | MANDRIVA:MDVSA-2008:141 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:141 | MANDRIVA:MDVSA-2008:142 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:142 | REDHAT:RHSA-2008:0561 | URL:http://www.redhat.com/support/errata/RHSA-2008-0561.html | SLACKWARE:SSA:2008-179-01 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.429562 | SUSE:SUSE-SR:2008:017 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html | UBUNTU:USN-621-1 | URL:http://www.ubuntu.com/usn/usn-621-1 | BID:29903 | URL:http://www.securityfocus.com/bid/29903 | OVAL:oval:org.mitre.oval:def:9959 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9959 | VUPEN:ADV-2008-1907 | URL:http://www.vupen.com/english/advisories/2008/1907/references | VUPEN:ADV-2008-1981 | URL:http://www.vupen.com/english/advisories/2008/1981/references | SECTRACK:1020347 | URL:http://www.securitytracker.com/id?1020347 | SECUNIA:30831 | URL:http://secunia.com/advisories/30831 | SECUNIA:30802 | URL:http://secunia.com/advisories/30802 | SECUNIA:31062 | URL:http://secunia.com/advisories/31062 | SECUNIA:31090 | URL:http://secunia.com/advisories/31090 | SECUNIA:31181 | URL:http://secunia.com/advisories/31181 | SECUNIA:31256 | URL:http://secunia.com/advisories/31256 | SECUNIA:31687 | URL:http://secunia.com/advisories/31687 | SECUNIA:30867 | URL:http://secunia.com/advisories/30867 | SECUNIA:30875 | URL:http://secunia.com/advisories/30875 | SECUNIA:30894 | URL:http://secunia.com/advisories/30894 | SECUNIA:33178 | URL:http://secunia.com/advisories/33178 | XF:ruby-rbarysplice-begrlen-code-execution(43351) | URL:http://xforce.iss.net/xforce/xfdb/43351",Assigned (20080616),"None (candidate not yet proposed)",
180| [CVE-2008-2751,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote attackers to inject arbitrary web script or HTML via the (1) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (2) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType, (3) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass, or (4) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc parameter to (a) resourceNode/customResourceNew.jsf] the (5) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (6) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType, (7) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass, (8) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiLookupProp:jndiLookup, or (9) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc parameter to (b) resourceNode/externalResourceNew.jsf
181| [CVE-2008-2952,Candidate,"liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams that trigger an assertion error.","BUGTRAQ:20080811 rPSA-2008-0249-1 openldap openldap-clients openldap-servers | URL:http://www.securityfocus.com/archive/1/archive/1/495320/100/0/threaded | MLIST:[oss-security] 20080713 Re: openldap DoS | URL:http://www.openwall.com/lists/oss-security/2008/07/13/2 | MISC:http://www.zerodayinitiative.com/advisories/ZDI-08-052/ | CONFIRM:http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5580] selectid=5580 | MLIST:[oss-security 20080701 Re: [oss-security] openldap DoS | URL:http://www.openwall.com/lists/oss-security/2008/07/01/2 | CONFIRM:http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5580 | CONFIRM:http://wiki.rpath.com/Advisories:rPSA-2008-0249 | CONFIRM:https://issues.rpath.com/browse/RPL-2645 | APPLE:APPLE-SA-2008-07-31 | URL:http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html | DEBIAN:DSA-1650 | URL:http://www.debian.org/security/2008/dsa-1650 | FEDORA:FEDORA-2008-6029 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00109.html | FEDORA:FEDORA-2008-6062 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00129.html | GENTOO:GLSA-200808-09 | URL:http://security.gentoo.org/glsa/glsa-200808-09.xml | MANDRIVA:MDVSA-2008:144 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:144 | REDHAT:RHSA-2008:0583 | URL:http://www.redhat.com/support/errata/RHSA-2008-0583.html | SUSE:SUSE-SR:2008:021 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.html | UBUNTU:USN-634-1 | URL:http://www.ubuntu.com/usn/usn-634-1 | BID:30013 | URL:http://www.securityfocus.com/bid/30013 | OVAL:oval:org.mitre.oval:def:10662 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10662 | VUPEN:ADV-2008-1978 | URL:http://www.vupen.com/english/advisories/2008/1978/references | VUPEN:ADV-2008-2268 | URL:http://www.vupen.com/english/advisories/2008/2268 | SECTRACK:1020405 | URL:http://www.securitytracker.com/id?1020405 | SECUNIA:30917 | URL:http://secunia.com/advisories/30917 | SECUNIA:30853 | URL:http://secunia.com/advisories/30853 | SECUNIA:31326 | URL:http://secunia.com/advisories/31326 | SECUNIA:31364 | URL:http://secunia.com/advisories/31364 | SECUNIA:31436 | URL:http://secunia.com/advisories/31436 | SECUNIA:32254 | URL:http://secunia.com/advisories/32254 | SECUNIA:32316 | URL:http://secunia.com/advisories/32316 | SECUNIA:30996 | URL:http://secunia.com/advisories/30996 | XF:openldap-bergetnext-dos(43515) | URL:http://xforce.iss.net/xforce/xfdb/43515",Assigned (20080701),"None (candidate not yet proposed)",
182| [CVE-2008-3081,Candidate,"Multiple unspecified ""input validation"" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration] (2) remote FTP storage settings
183| [CVE-2008-3312,Candidate,"Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. NOTE: this might be an issue in FCKeditor.","MISC:http://www.securityfocus.com/bid/30285/exploit | BID:30285 | URL:http://www.securityfocus.com/bid/30285 | XF:lemoncms-browser-file-include(43907) | URL:http://xforce.iss.net/xforce/xfdb/43907",Assigned (20080725),"None (candidate not yet proposed)",
184| [CVE-2008-3511,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php] and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE: the provenance of this information is unknown
185| [CVE-2008-3666,Candidate,"Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured] and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.","SUNALERT:239186 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-239186-1 | BID:30654 | URL:http://www.securityfocus.com/bid/30654 | OSVDB:47375 | URL:http://osvdb.org/47375 | OVAL:oval:org.mitre.oval:def:5128 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5128 | VUPEN:ADV-2008-2337 | URL:http://www.vupen.com/english/advisories/2008/2337 | SECTRACK:1020666 | URL:http://www.securitytracker.com/id?1020666 | SECUNIA:31426 | URL:http://secunia.com/advisories/31426 | XF:sun-solaris-sendfilev-dos(44396) | URL:http://xforce.iss.net/xforce/xfdb/44396",Assigned (20080813),"None (candidate not yet proposed)",
186| [CVE-2008-3707,Candidate,"Multiple PHP remote file inclusion vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to execute arbitrary PHP code via a URL in the script_path parameter to (1) flat_read.php, (2) post.php, (3) process_post.php, (4) process_search.php, (5) forum.php, (6) process_subscribe.php, (7) read.php, (8) search.php, (9) subscribe.php in path/] and (10) add_ban.php, (11) add_ban_form.php, (12) add_board.php, (13) add_vip.php, (14) add_vip_form.php, (15) copy_ban.php, (16) copy_vip.php, (17) delete_ban.php, (18) delete_board.php, (19) delete_messages.php, (20) delete_vip.php, (21) edit_ban.php, (22) edit_board.php, (23) edit_vip.php, (24) index.php, (25) lock_messages.php, (26) login.php, (27) modify_ban_list.php, (28) modify_vip_list.php, (29) move_messages.php, (30) process_add_board.php, (31) process_ban.php, (32) process_delete_ban.php, (33) process_delete_board.php, (34) process_delete_messages.php, (35) process_delete_vip.php, (36) process_edit_board.php, (37) process_lock_messages.php, (38) process_login.php, (39) process_move_messages.php, (40) process_sticky_messages.php, (41) process_vip.php, and (42) sticky_messages.php in path/adminopts. NOTE: the include/common.php vector is covered by CVE-2006-2871. NOTE: some of these vectors might not be vulnerabilities under proper installation.","MISC:http://packetstormsecurity.org/0808-exploits/cyboards-rfilfixss.txt | VIM:20080819 CyBoards PHP uncertainties (RFI/path traversal) | URL:http://www.attrition.org/pipermail/vim/2008-August/002052.html | BID:30688 | URL:http://www.securityfocus.com/bid/30688 | XF:cyboardsphplite-scriptpath-file-include(44474) | URL:http://xforce.iss.net/xforce/xfdb/44474",Assigned (20080819),"None (candidate not yet proposed)",
187| [CVE-2008-3709,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to inject arbitrary web script or HTML via the (1) lOptionsOptions, (2) lNavAdminOptions, or (3) lNavReturn parameter to options.php] or the (4) lNavReturn parameter to subscribe.php.","MISC:http://packetstormsecurity.org/0808-exploits/cyboards-rfilfixss.txt | VIM:20080819 CyBoards PHP uncertainties (RFI/path traversal) | URL:http://www.attrition.org/pipermail/vim/2008-August/002052.html | BID:30688 | URL:http://www.securityfocus.com/bid/30688 | XF:cyboardsphplite-options-subscribe-xss(44476) | URL:http://xforce.iss.net/xforce/xfdb/44476",Assigned (20080819),"None (candidate not yet proposed)",
188| [CVE-2008-3831,Candidate,"The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD does not restrict the DRM_I915_HWS_ADDR ioctl to the Direct Rendering Manager (DRM) master, which allows local users to cause a denial of service (memory corruption) via a crafted ioctl call, related to absence of the DRM_MASTER and DRM_ROOT_ONLY flags in the ioctl's configuration.","BUGTRAQ:20081112 rPSA-2008-0316-1 kernel | URL:http://www.securityfocus.com/archive/1/archive/1/498285/100/0/threaded | MLIST:[source-changes] 20081017 CVS: cvs.openbsd.org: src | URL:http://archives.neohapsis.com/archives/openbsd/cvs/2008-10/0365.html | CONFIRM:http://security.debian.org/pool/updates/main/l/linux-2.6.24/linux-2.6.24_2.6.24-6~etchnhalf.6.diff.gz | CONFIRM:http://www.openbsd.org/cgi-bin/cvsweb/src/sys/dev/pci/drm/i915_drv.c | CONFIRM:http://www.openbsd.org/cgi-bin/cvsweb/src/sys/dev/pci/drm/i915_drv.c.diff?r1=1.7] r2=1.8 | CONFIRM:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0316 | CONFIRM:http://wiki.rpath.com/Advisories:rPSA-2008-0316 | DEBIAN:DSA-1655 | URL:http://www.debian.org/security/2008/dsa-1655 | FEDORA:FEDORA-2008-8929 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00693.html | FEDORA:FEDORA-2008-8980 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00689.html | MANDRIVA:MDVSA-2008:224 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:224 | REDHAT:RHSA-2008:1017 | URL:http://www.redhat.com/support/errata/RHSA-2008-1017.html | REDHAT:RHSA-2009:0009 | URL:http://www.redhat.com/support/errata/RHSA-2009-0009.html | SUNALERT:245846 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-245846-1 | UBUNTU:USN-659-1 | URL:http://www.ubuntu.com/usn/usn-659-1 | UBUNTU:USN-679-1 | URL:http://www.ubuntu.com/usn/usn-679-1 | BID:31792 | URL:http://www.securityfocus.com/bid/31792 | OVAL:oval:org.mitre.oval:def:11542 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11542 | SECTRACK:1021065 | URL:http://securitytracker.com/id?1021065 | SECUNIA:32386 | URL:http://secunia.com/advisories/32386 | SECUNIA:32709 | URL:http://secunia.com/advisories/32709 | SECUNIA:32918 | URL:http://secunia.com/advisories/32918 | SECUNIA:33182 | URL:http://secunia.com/advisories/33182 | SECUNIA:33586 | URL:http://secunia.com/advisories/33586 | SECUNIA:32315 | URL:http://secunia.com/advisories/32315",Assigned (20080827),"None (candidate not yet proposed)",
189| [CVE-2008-3851,Candidate,"Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the (1) blogpost, (2) cat, and (3) file parameters to data/inc/themes/predefined_variables.php, as reachable through index.php] and the (4) blogpost and (5) cat parameters to data/inc/blog_include_react.php, as reachable through index.php. NOTE: the issue involving vectors 1 through 3 reportedly exists because of an incomplete fix for CVE-2008-3194.","BUGTRAQ:20080825 [DSECRG-08-037] Multiple Local File Include Vulnerabilities in Pluck CMS 4.5.2 | URL:http://www.securityfocus.com/archive/1/archive/1/495706/100/0/threaded | MILW0RM:6300 | URL:http://www.milw0rm.com/exploits/6300 | CONFIRM:http://www.pluck-cms.org/releasenotes.php#4.5.3 | BID:30820 | URL:http://www.securityfocus.com/bid/30820 | SECUNIA:31607 | URL:http://secunia.com/advisories/31607 | SREASON:4195 | URL:http://securityreason.com/securityalert/4195 | XF:pluck-index-file-include(44677) | URL:http://xforce.iss.net/xforce/xfdb/44677",Assigned (20080827),"None (candidate not yet proposed)",
190| [CVE-2008-4101,Candidate,"Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ""] "" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) ""Ctrl-]"" (control close-square-bracket) or (3) ""g]"" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.","BUGTRAQ:20080822 Vim: Arbitrary Code Execution in Commands: K, Control-], g] | URL:http://www.securityfocus.com/archive/1/495662 | BUGTRAQ:20080825 RE: Arbitrary Code Execution in Commands: K, Control-], g] | URL:http://www.securityfocus.com/archive/1/495703 | BUGTRAQ:20090401 VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim | URL:http://www.securityfocus.com/archive/1/archive/1/502322/100/0/threaded | MLIST:[oss-security] 20080911 Re: [oss-list] CVE request (vim) | URL:http://www.openwall.com/lists/oss-security/2008/09/11/4 | MLIST:[oss-security] 20080911 [oss-list] CVE request (vim) | URL:http://www.openwall.com/lists/oss-security/2008/09/11/3 | MLIST:[oss-security] 20080915 Re: [oss-list] CVE request (vim) | URL:http://www.openwall.com/lists/oss-security/2008/09/16/5 | MLIST:[oss-security] 20080915 Re: [oss-list] CVE request (vim) | URL:http://www.openwall.com/lists/oss-security/2008/09/16/6 | MLIST:[vim-dev] 20080903 Patch 7.2.010 | URL:http://ftp.vim.org/pub/vim/patches/7.2/7.2.010 | MLIST:[vim_dev] 20080824 Bug with v_K and potentially K command | URL:http://groups.google.com/group/vim_dev/msg/9290f26f9bc11b33 | MISC:http://groups.google.com/group/vim_dev/attach/9290f26f9bc11b33/K-arbitrary-command-execution.patch.v3?part=2 | MISC:http://groups.google.com/group/vim_dev/attach/dd32ad3a84f36bb2/K-arbitrary-command-execution.patch?part=2 | MISC:http://groups.google.com/group/vim_dev/browse_thread/thread/1434d0812b5c817e/6ad2d5b50a96668e | MISC:http://www.rdancer.org/vulnerablevim-K.html | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=461927 | CONFIRM:http://support.apple.com/kb/HT3216 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2009-001.htm | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2008-457.htm | CONFIRM:http://www.vmware.com/security/advisories/VMSA-2009-0004.html | CONFIRM:http://support.apple.com/kb/HT4077 | APPLE:APPLE-SA-2008-10-09 | URL:http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html | APPLE:APPLE-SA-2010-03-29-1 | URL:http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html | MANDRIVA:MDVSA-2008:236 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:236 | REDHAT:RHSA-2008:0617 | URL:http://www.redhat.com/support/errata/RHSA-2008-0617.html | REDHAT:RHSA-2008:0580 | URL:http://www.redhat.com/support/errata/RHSA-2008-0580.html | REDHAT:RHSA-2008:0618 | URL:http://www.redhat.com/support/errata/RHSA-2008-0618.html | UBUNTU:USN-712-1 | URL:http://www.ubuntu.com/usn/USN-712-1 | BID:31681 | URL:http://www.securityfocus.com/bid/31681 | BID:30795 | URL:http://www.securityfocus.com/bid/30795 | OVAL:oval:org.mitre.oval:def:10894 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10894 | OVAL:oval:org.mitre.oval:def:5812 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5812 | SECUNIA:31592 | URL:http://secunia.com/advisories/31592 | SECUNIA:32858 | URL:http://secunia.com/advisories/32858 | SECUNIA:32864 | URL:http://secunia.com/advisories/32864 | VUPEN:ADV-2008-2780 | URL:http://www.vupen.com/english/advisories/2008/2780 | VUPEN:ADV-2009-0033 | URL:http://www.vupen.com/english/advisories/2009/0033 | SECUNIA:32222 | URL:http://secunia.com/advisories/32222 | SECUNIA:33410 | URL:http://secunia.com/advisories/33410 | VUPEN:ADV-2009-0904 | URL:http://www.vupen.com/english/advisories/2009/0904 | XF:vim-normal-command-execution(44626) | URL:http://xforce.iss.net/xforce/xfdb/44626",Assigned (20080915),"None (candidate not yet proposed)",
191| [CVE-2008-4610,Candidate,"MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac] or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718.","MLIST:[oss-security] 20081007 CVE request: crashers / potential security risks in mplayer | URL:http://www.openwall.com/lists/oss-security/2008/10/07/1 | UBUNTU:USN-734-1 | URL:http://www.ubuntu.com/usn/USN-734-1 | SECUNIA:34296 | URL:http://secunia.com/advisories/34296",Assigned (20081020),"None (candidate not yet proposed)",
192| [CVE-2008-4761,Candidate,"Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. NOTE: this issue is probably in the HTMLArea HTMLTidy (HTML Tidy) plugin, not eSupport.","MLIST:[oss-security] 20081027 XSS in HTML Tidy plugin used in WYSIWYG HTML editors | URL:http://www.openwall.com/lists/oss-security/2008/10/27/6 | MISC:http://downloads.securityfocus.com/vulnerabilities/exploits/31908.html | BID:31908 | URL:http://www.securityfocus.com/bid/31908 | XF:esupport-htmltidylogic-xss(46097) | URL:http://xforce.iss.net/xforce/xfdb/46097",Assigned (20081027),"None (candidate not yet proposed)",
193| [CVE-2008-4810,Candidate,"The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrary PHP code via vectors related to templates and (1) a dollar-sign character, aka ""php executed in templates] "" and (2) a double quoted literal string, aka a ""function injection security hole."" NOTE: each vector affects slightly different SVN revisions.","MLIST:[oss-security] 20081025 Regarding SA32329 (Smarty ""_expand_quoted_text()"" Security Bypass) | URL:http://www.openwall.com/lists/oss-security/2008/10/25/2 | MISC:http://securityvulns.ru/Udocument746.html | CONFIRM:http://code.google.com/p/smarty-php/source/detail?r=2784&path=/trunk/libs/Smarty_Compiler.class.php | CONFIRM:http://code.google.com/p/smarty-php/source/detail?r=2797&path=/trunk/libs/Smarty_Compiler.class.php | CONFIRM:http://smarty-php.googlecode.com/svn/trunk/NEWS | CONFIRM:https://bugs.gentoo.org/attachment.cgi?id=169804&action=view | DEBIAN:DSA-1691 | URL:http://www.debian.org/security/2008/dsa-1691 | BID:31862 | URL:http://www.securityfocus.com/bid/31862 | SECUNIA:32329 | URL:http://secunia.com/advisories/32329 | XF:smarty-expandquotedtext-code-execution(46031) | URL:http://xforce.iss.net/xforce/xfdb/46031",Assigned (20081031),"None (candidate not yet proposed)",
194| [CVE-2008-4872,Candidate,"Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","SECUNIA:28780 | URL:http://secunia.com/advisories/28780 | XF:itechbids-bidhistory-xss(46320) | URL:http://xforce.iss.net/xforce/xfdb/46320",Assigned (20081031),"None (candidate not yet proposed)",
195| [CVE-2008-5005,Candidate,"Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension argument on the command line to the tmail or dmail program] and (b) remote attackers to execute arbitrary code by sending e-mail to a destination mailbox name composed of a username and '+' character followed by a long string, processed by the tmail or possibly dmail program.","BUGTRAQ:20081103 Bitsec Security Advisory: UW/Panda IMAP [dt]mail buffer overflow | URL:http://www.securityfocus.com/archive/1/archive/1/498002/100/0/threaded | FULLDISC:20081103 Bitsec Security Advisory: UW/Panda IMAP [dt]mail buffer overflow | URL:http://marc.info/?l=full-disclosure&m=122572590212610&w=4 | MLIST:[imap-uw] 20081031 Security bug in tmail and dmail | URL:http://mailman2.u.washington.edu/pipermail/imap-uw/2008-October/002267.html | MLIST:[imap-uw] 20081031 Security bug in tmail and dmail | URL:http://mailman2.u.washington.edu/pipermail/imap-uw/2008-October/002268.html | MLIST:[oss-security] 20081103 CVE request - uw-imap | URL:http://www.openwall.com/lists/oss-security/2008/11/03/3 | MLIST:[oss-security] 20081103 Re: CVE request - uw-imap | URL:http://www.openwall.com/lists/oss-security/2008/11/03/4 | MLIST:[oss-security] 20081103 Re: CVE request - uw-imap | URL:http://www.openwall.com/lists/oss-security/2008/11/03/5 | MISC:http://www.bitsec.com/en/rad/bsa-081103.c | MISC:http://www.bitsec.com/en/rad/bsa-081103.txt | MISC:http://www.washington.edu/alpine/tmailbug.html | CONFIRM:http://panda.com/imap/ | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=469667 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2009-065.htm | DEBIAN:DSA-1685 | URL:http://www.debian.org/security/2008/dsa-1685 | FEDORA:FEDORA-2008-9383 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00058.html | FEDORA:FEDORA-2008-9396 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00082.html | MANDRIVA:MDVSA-2009:146 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:146 | REDHAT:RHSA-2009:0275 | URL:http://rhn.redhat.com/errata/RHSA-2009-0275.html | BID:32072 | URL:http://www.securityfocus.com/bid/32072 | OVAL:oval:org.mitre.oval:def:10485 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10485 | VUPEN:ADV-2008-3042 | URL:http://www.vupen.com/english/advisories/2008/3042 | SECTRACK:1021131 | URL:http://securitytracker.com/id?1021131 | SECUNIA:32483 | URL:http://secunia.com/advisories/32483 | SECUNIA:32512 | URL:http://secunia.com/advisories/32512 | SECUNIA:33142 | URL:http://secunia.com/advisories/33142 | SECUNIA:33996 | URL:http://secunia.com/advisories/33996 | SREASON:4570 | URL:http://securityreason.com/securityalert/4570 | XF:uwimapd-tmail-bo(46281) | URL:http://xforce.iss.net/xforce/xfdb/46281",Assigned (20081110),"None (candidate not yet proposed)",
196| [CVE-2008-5095,Candidate,"Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1] and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.","CONFIRM:http://www.novell.com/support/viewContent.do?externalId=7001157&sliceId=1 | BID:30947 | URL:http://www.securityfocus.com/bid/30947 | SECTRACK:1020792 | URL:http://www.securitytracker.com/id?1020792 | SECTRACK:1020793 | URL:http://www.securitytracker.com/id?1020793",Assigned (20081114),"None (candidate not yet proposed)",
197| [CVE-2008-5232,Candidate,"Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","MISC:http://www.securityfocus.com/data/vulnerabilities/exploits/30814.html.txt | MISC:http://packetstormsecurity.org/0808-exploits/wms-overflow.txt | BID:30814 | URL:http://www.securityfocus.com/bid/30814 | SECTRACK:1020733 | URL:http://securitytracker.com/id?1020733 | XF:windowsmediaservices-callhtmlhelp-bo(44629) | URL:http://xforce.iss.net/xforce/xfdb/44629",Assigned (20081125),"None (candidate not yet proposed)",
198| [CVE-2008-5712,Candidate,"The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element] or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element. NOTE: the FONT vector is already covered by CVE-2008-4514.","MILW0RM:6704 | URL:http://www.milw0rm.com/exploits/6704 | SREASON:4806 | URL:http://securityreason.com/securityalert/4806 | XF:konqueror-htmlparser-dos(47696) | URL:http://xforce.iss.net/xforce/xfdb/47696",Assigned (20081224),"None (candidate not yet proposed)",
199| [CVE-2008-5789,Candidate,"Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/] and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.","MILW0RM:7040 | URL:http://www.milw0rm.com/exploits/7040 | BID:32194 | URL:http://www.securityfocus.com/bid/32194 | SREASON:4827 | URL:http://securityreason.com/securityalert/4827 | XF:feederator-mosconfigabsolute-file-include(46438) | URL:http://xforce.iss.net/xforce/xfdb/46438",Assigned (20081230),"None (candidate not yet proposed)",
200| [CVE-2008-5949,Candidate,"Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the cct_base parameter to (1) index.php] (2) handle/proxy.php
201| [CVE-2008-6073,Candidate,"StorageCrypt 2.0.1 does not properly encrypt disks, which allows local users to obtain sensitive information via unspecified vectors. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","SECUNIA:30471 | URL:http://secunia.com/advisories/30471 | XF:storagecrypt-unspecified-weak-security(42905) | URL:http://xforce.iss.net/xforce/xfdb/42905",Assigned (20090205),"None (candidate not yet proposed)",
202| [CVE-2008-6545,Candidate,"PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:28631 | URL:http://www.securityfocus.com/bid/28631 | OSVDB:53093 | URL:http://www.osvdb.org/53093 | XF:webservercreator-createdb-file-include(43555) | URL:http://xforce.iss.net/xforce/xfdb/43555",Assigned (20090329),"None (candidate not yet proposed)",
203| [CVE-2008-6573,Candidate,"Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface] and allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to (2) permissions for SPIM profiles in the web interface and (3) a crafted SIP request to the SIP server.","MISC:http://www.voipshield.com/research-details.php?id=22 | MISC:http://www.voipshield.com/research-details.php?id=25 | MISC:http://www.voipshield.com/research-details.php?id=26 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2008-150.htm | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2008-151.htm | BID:28682 | URL:http://www.securityfocus.com/bid/28682 | OSVDB:44284 | URL:http://osvdb.org/44284 | OSVDB:44285 | URL:http://osvdb.org/44285 | OSVDB:44286 | URL:http://osvdb.org/44286 | SECUNIA:29744 | URL:http://secunia.com/advisories/29744 | XF:avaya-ses-sip-sql-injection(41733) | URL:http://xforce.iss.net/xforce/xfdb/41733 | XF:avaya-ses-spim-sql-injection(41730) | URL:http://xforce.iss.net/xforce/xfdb/41730",Assigned (20090401),"None (candidate not yet proposed)",
204| [CVE-2008-6777,Candidate,"Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php] and the (4) quote parameter in a post action and (5) pid parameter in an edit action to post.php, different vectors than CVE-2005-0413.2 and CVE-2007-6667.","MILW0RM:6879 | URL:http://www.milw0rm.com/exploits/6879 | BID:31995 | URL:http://www.securityfocus.com/bid/31995 | SECUNIA:28280 | URL:http://secunia.com/advisories/28280 | XF:myphpforum-post-member-sql-injection(46238) | URL:http://xforce.iss.net/xforce/xfdb/46238",Assigned (20090501),"None (candidate not yet proposed)",
205| [CVE-2008-6786,Candidate,"Multiple directory traversal vulnerabilities in geekigeeki.py in GeekiGeeki before 3.0 allow remote attackers to read arbitrary files via directory traversal sequences in a pagename argument in the (1) handle_edit and (2) handle_raw functions.","CONFIRM:http://www.codewiz.org/wikigit/geekigeeki.git/blobdiff/92e45c3ce9260c69b4201d877c0f2e431024a52e..5f99f96a7a102bb8f2c491dd1e11fe8686c7c0a0:/geekigeeki.py | CONFIRM:http://www.codewiz.org/wikigit/geekigeeki.git?a=commit] h=5f99f96a7a102bb8f2c491dd1e11fe8686c7c0a0 | BID:32831 | URL:http://www.securityfocus.com/bid/32831 | OSVDB:50719 | URL:http://www.osvdb.org/50719 | SECUNIA:33162 | URL:http://secunia.com/advisories/33162 | XF:geekigeeki-handleedit-directory-traversal(47375) | URL:http://xforce.iss.net/xforce/xfdb/47375",Assigned (20090501),"None (candidate not yet proposed)",
206| [CVE-2008-6807,Candidate,"PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to execute arbitrary PHP code via a URL in the xml_dir parameter. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information. NOTE: the lib_dir vector is already covered by CVE-2006-6630.","BID:31883 | URL:http://www.securityfocus.com/bid/31883 | XF:osprey-listrecords-file-include(46066) | URL:http://xforce.iss.net/xforce/xfdb/46066",Assigned (20090512),"None (candidate not yet proposed)",
207| [CVE-2008-7139,Candidate,"Multiple cross-site request forgery (CSRF) vulnerabilities in WS-Proxy in Eye-Fi 1.1.2 allow remote attackers to hijack the authentication of users for requests that modify configuration via a SOAPAction parameter of (1) urn:SetOptions for autostart, (2) urn:SetDesktopSync for file upload, or (3) urn:SetFolderConfig for file download location or modification of authentication credentials] and (4) urn:AddNetwork for adding an arbitrary Service Set Identifier (SSID) to hijack the image upload.","BUGTRAQ:20080303 Airscanner Mobile Security Advisory #07122001: Eye-Fi Multiple Vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/489045/100/0/threaded | MISC:http://www.informit.com/articles/article.aspx?p=1177111 | BID:28085 | URL:http://www.securityfocus.com/bid/28085 | OSVDB:42718 | URL:http://osvdb.org/42718 | SECUNIA:29221 | URL:http://secunia.com/advisories/29221 | XF:eyefimanager-wsproxy-csrf(40995) | URL:http://xforce.iss.net/xforce/xfdb/40995",Assigned (20090901),"None (candidate not yet proposed)",
208| [CVE-2008-7210,Candidate,"directory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL injection attacks via a numeric parameter with a value matching the s parameter's hash value, which prevents the associated $_GET[""s""] variable from being unset. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP] if so, then this should not be treated as a vulnerability in AJChat.","MILW0RM:4890 | URL:http://www.milw0rm.com/exploits/4890 | BID:27241 | URL:http://www.securityfocus.com/bid/27241 | XF:ajchat-directory-sql-injection(39600) | URL:http://xforce.iss.net/xforce/xfdb/39600",Assigned (20090911),"None (candidate not yet proposed)",
209| [CVE-2008-7238,Candidate,"Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.3 allow (1) local users to affect confidentiality and integrity via unknown vectors related to the Mobile Application Server component (APP01)] (2) remote attackers to affect confidentiality via unknown vectors related to the Oracle Applications Framework (APP03)
210| [CVE-2009-0773,Candidate,"The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains ""some non-set elements,"" which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption] (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault
211| [CVE-2009-1097,Candidate,"Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996] and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.","IDEFENSE:20090326 Sun Java Web Start (JWS ) PNG Decoding Integer Overflow Vulnerability | URL:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=780 | IDEFENSE:20090326 Sun Java Runtine Environment (JRE) GIF Decoding Heap Corruption Vulnerability | URL:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=779 | BUGTRAQ:20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components | URL:http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm | CONFIRM:http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html | CONFIRM:http://www.vmware.com/security/advisories/VMSA-2009-0016.html | DEBIAN:DSA-1769 | URL:http://www.debian.org/security/2009/dsa-1769 | GENTOO:GLSA-200911-02 | URL:http://security.gentoo.org/glsa/glsa-200911-02.xml | HP:HPSBMA02429 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133 | HP:SSRT090058 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133 | HP:HPSBUX02429 | URL:http://marc.info/?l=bugtraq&m=124344236532162&w=2 | MANDRIVA:MDVSA-2009:137 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:137 | MANDRIVA:MDVSA-2009:162 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:162 | REDHAT:RHSA-2009:0392 | URL:http://www.redhat.com/support/errata/RHSA-2009-0392.html | REDHAT:RHSA-2009:0377 | URL:https://rhn.redhat.com/errata/RHSA-2009-0377.html | REDHAT:RHSA-2009:1038 | URL:http://www.redhat.com/support/errata/RHSA-2009-1038.html | REDHAT:RHSA-2009:1198 | URL:https://rhn.redhat.com/errata/RHSA-2009-1198.html | SUNALERT:254571 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-254571-1 | SUSE:SUSE-SA:2009:016 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html | SUSE:SUSE-SA:2009:029 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html | SUSE:SUSE-SA:2009:036 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html | UBUNTU:USN-748-1 | URL:http://www.ubuntu.com/usn/usn-748-1 | BID:34240 | URL:http://www.securityfocus.com/bid/34240 | OVAL:oval:org.mitre.oval:def:11241 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11241 | OVAL:oval:org.mitre.oval:def:6288 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6288 | SECTRACK:1021913 | URL:http://www.securitytracker.com/id?1021913 | SECUNIA:34489 | URL:http://secunia.com/advisories/34489 | SECUNIA:34496 | URL:http://secunia.com/advisories/34496 | SECUNIA:34675 | URL:http://secunia.com/advisories/34675 | SECUNIA:34632 | URL:http://secunia.com/advisories/34632 | SECUNIA:35223 | URL:http://secunia.com/advisories/35223 | SECUNIA:35156 | URL:http://secunia.com/advisories/35156 | SECUNIA:35255 | URL:http://secunia.com/advisories/35255 | SECUNIA:35776 | URL:http://secunia.com/advisories/35776 | SECUNIA:36185 | URL:http://secunia.com/advisories/36185 | SECUNIA:37386 | URL:http://secunia.com/advisories/37386 | SECUNIA:37460 | URL:http://secunia.com/advisories/37460 | VUPEN:ADV-2009-1426 | URL:http://www.vupen.com/english/advisories/2009/1426 | VUPEN:ADV-2009-3316 | URL:http://www.vupen.com/english/advisories/2009/3316 | XF:jre-gif-file-bo(49475) | URL:http://xforce.iss.net/xforce/xfdb/49475",Assigned (20090325),"None (candidate not yet proposed)",
212| [CVE-2009-1304,Candidate,"The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date] and (2) js_CheckRedeclaration.","CONFIRM:http://www.mozilla.org/security/announce/2009/mfsa2009-14.html | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=461158 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=475971 | DEBIAN:DSA-1797 | URL:http://www.debian.org/security/2009/dsa-1797 | FEDORA:FEDORA-2009-3875 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html | MANDRIVA:MDVSA-2009:111 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:111 | MANDRIVA:MDVSA-2009:141 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:141 | REDHAT:RHSA-2009:0436 | URL:http://www.redhat.com/support/errata/RHSA-2009-0436.html | SLACKWARE:SSA:2009-178-01 | URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275 | SUNALERT:264308 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1 | SUSE:SUSE-SR:2009:010 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html | UBUNTU:USN-764-1 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-764-1 | BID:34656 | URL:http://www.securityfocus.com/bid/34656 | OVAL:oval:org.mitre.oval:def:5319 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5319 | OVAL:oval:org.mitre.oval:def:5480 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5480 | OVAL:oval:org.mitre.oval:def:6015 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6015 | OVAL:oval:org.mitre.oval:def:7516 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7516 | OVAL:oval:org.mitre.oval:def:9535 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9535 | SECTRACK:1022090 | URL:http://www.securitytracker.com/id?1022090 | SECUNIA:34758 | URL:http://secunia.com/advisories/34758 | SECUNIA:34894 | URL:http://secunia.com/advisories/34894 | SECUNIA:34843 | URL:http://secunia.com/advisories/34843 | SECUNIA:34780 | URL:http://secunia.com/advisories/34780 | SECUNIA:35065 | URL:http://secunia.com/advisories/35065 | SECUNIA:35042 | URL:http://secunia.com/advisories/35042 | SECUNIA:35602 | URL:http://secunia.com/advisories/35602 | VUPEN:ADV-2009-1125 | URL:http://www.vupen.com/english/advisories/2009/1125",Assigned (20090416),"None (candidate not yet proposed)",
213| [CVE-2009-1460,Candidate,"razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the administrator's password hash and FTP user credentials] and (2) the root directory, (3) datastore/, and (4) admin/core/, which allows local users to have an unspecified impact.","FULLDISC:20090416 [follow-up] razorCMS - Multiple Vulnerabilities | URL:http://marc.info/?l=full-disclosure&m=123998062108561&w=2 | FULLDISC:20090416 razorCMS - Multiple Vulnerabilities | URL:http://marc.info/?l=full-disclosure&m=123990481506680&w=2 | CONFIRM:http://razorcms.co.uk/support/viewtopic.php?f=13&t=325 | BID:34566 | URL:http://www.securityfocus.com/bid/34566 | OSVDB:53777 | URL:http://osvdb.org/53777 | SECUNIA:34744 | URL:http://secunia.com/advisories/34744 | XF:razorcms-adminconfig-info-disclosure(49946) | URL:http://xforce.iss.net/xforce/xfdb/49946",Assigned (20090428),"None (candidate not yet proposed)",
214| [CVE-2009-1632,Candidate,"Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c] and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.","MLIST:[ipsec-tools-announce] 20090422 Ipsec-tools 0.7.2 released | URL:http://sourceforge.net/mailarchive/forum.php?thread_name=20090422151825.GB46988%40zeninc.net&forum_name=ipsec-tools-announce | MLIST:[oss-security] 20090429 ipsec-tools 0.7.2 | URL:http://marc.info/?l=oss-security&m=124101704828036&w=2 | MLIST:[oss-security] 20090512 Re: ipsec-tools 0.7.2 | URL:http://www.openwall.com/lists/oss-security/2009/05/12/3 | CONFIRM:http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/crypto_openssl.c | CONFIRM:http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/crypto_openssl.c.diff?r1=1.11.6.4&r2=1.11.6.5&f=h | CONFIRM:http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/nattraversal.c | CONFIRM:http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/nattraversal.c.diff?r1=1.6&r2=1.6.6.1&f=h | CONFIRM:http://sourceforge.net/project/shownotes.php?group_id=74601&release_id=677611 | CONFIRM:https://trac.ipsec-tools.net/ticket/303 | CONFIRM:http://support.apple.com/kb/HT3937 | APPLE:APPLE-SA-2009-11-09-1 | URL:http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html | DEBIAN:DSA-1804 | URL:http://www.debian.org/security/2009/dsa-1804 | GENTOO:GLSA-200905-03 | URL:http://security.gentoo.org/glsa/glsa-200905-03.xml | MANDRIVA:MDVSA-2009:114 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:114 | REDHAT:RHSA-2009:1036 | URL:http://www.redhat.com/support/errata/RHSA-2009-1036.html | SUSE:SUSE-SR:2009:012 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html | UBUNTU:USN-785-1 | URL:http://www.ubuntu.com/usn/USN-785-1 | BID:34765 | URL:http://www.securityfocus.com/bid/34765 | OVAL:oval:org.mitre.oval:def:10581 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10581 | SECUNIA:35153 | URL:http://secunia.com/advisories/35153 | SECUNIA:35159 | URL:http://secunia.com/advisories/35159 | SECUNIA:35212 | URL:http://secunia.com/advisories/35212 | SECUNIA:35404 | URL:http://secunia.com/advisories/35404 | SECUNIA:35685 | URL:http://secunia.com/advisories/35685 | VUPEN:ADV-2009-3184 | URL:http://www.vupen.com/english/advisories/2009/3184",Assigned (20090514),"None (candidate not yet proposed)",
215| [CVE-2009-1656,Candidate,"Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275] and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka ""command injection vulnerability.""","CONFIRM:http://www.xerox.com/downloads/usa/en/c/cert_XRX09-02_v1.0.pdf | BID:34984 | URL:http://www.securityfocus.com/bid/34984 | OSVDB:54457 | URL:http://osvdb.org/54457 | SECTRACK:1022238 | URL:http://www.securitytracker.com/id?1022238 | SECUNIA:35101 | URL:http://secunia.com/advisories/35101 | VUPEN:ADV-2009-1328 | URL:http://www.vupen.com/english/advisories/2009/1328 | XF:workcentre-unspecified-cmd-execution(50558) | URL:http://xforce.iss.net/xforce/xfdb/50558",Assigned (20090516),"None (candidate not yet proposed)",
216| [CVE-2009-1833,Candidate,"The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c] and other vectors.","CONFIRM:http://www.mozilla.org/security/announce/2009/mfsa2009-24.html | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=369696 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=426520 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=427196 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=487204 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=503570 | DEBIAN:DSA-1820 | URL:http://www.debian.org/security/2009/dsa-1820 | FEDORA:FEDORA-2009-6366 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html | FEDORA:FEDORA-2009-6411 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html | MANDRIVA:MDVSA-2009:141 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:141 | REDHAT:RHSA-2009:1095 | URL:https://rhn.redhat.com/errata/RHSA-2009-1095.html | REDHAT:RHSA-2009:1096 | URL:http://rhn.redhat.com/errata/RHSA-2009-1096.html | REDHAT:RHSA-2009:1125 | URL:http://www.redhat.com/support/errata/RHSA-2009-1125.html | REDHAT:RHSA-2009:1126 | URL:http://www.redhat.com/support/errata/RHSA-2009-1126.html | SLACKWARE:SSA:2009-167-01 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468 | SLACKWARE:SSA:2009-176-01 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408 | SLACKWARE:SSA:2009-178-01 | URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275 | SUNALERT:265068 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1 | SUNALERT:1020800 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1 | UBUNTU:USN-782-1 | URL:http://www.ubuntu.com/usn/usn-782-1 | BID:35326 | URL:http://www.securityfocus.com/bid/35326 | BID:35372 | URL:http://www.securityfocus.com/bid/35372 | OSVDB:55152 | URL:http://osvdb.org/55152 | OSVDB:55153 | URL:http://osvdb.org/55153 | OSVDB:55154 | URL:http://osvdb.org/55154 | OVAL:oval:org.mitre.oval:def:11487 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11487 | SECTRACK:1022376 | URL:http://securitytracker.com/id?1022376 | SECTRACK:1022397 | URL:http://www.securitytracker.com/id?1022397 | SECUNIA:35331 | URL:http://secunia.com/advisories/35331 | SECUNIA:35428 | URL:http://secunia.com/advisories/35428 | SECUNIA:35431 | URL:http://secunia.com/advisories/35431 | SECUNIA:35439 | URL:http://secunia.com/advisories/35439 | SECUNIA:35440 | URL:http://secunia.com/advisories/35440 | SECUNIA:35468 | URL:http://secunia.com/advisories/35468 | SECUNIA:35536 | URL:http://secunia.com/advisories/35536 | SECUNIA:35415 | URL:http://secunia.com/advisories/35415 | SECUNIA:35561 | URL:http://secunia.com/advisories/35561 | SECUNIA:35602 | URL:http://secunia.com/advisories/35602 | VUPEN:ADV-2009-1572 | URL:http://www.vupen.com/english/advisories/2009/1572 | VUPEN:ADV-2009-2152 | URL:http://www.vupen.com/english/advisories/2009/2152",Assigned (20090529),"None (candidate not yet proposed)",
217| [CVE-2009-1844,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.18 and 6.x before 6.12 allow (1) remote authenticated users to inject arbitrary web script or HTML via crafted UTF-8 byte sequences that are treated as UTF-7 by Internet Explorer 6 and 7, which are not properly handled in the ""HTML exports of books"" feature] and (2) allow remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via the help text of an arbitrary vocabulary. NOTE: vector 1 exists because of an incomplete fix for CVE-2009-1575.","CONFIRM:http://drupal.org/node/461886 | DEBIAN:DSA-1808 | URL:http://www.debian.org/security/2009/dsa-1808 | SECUNIA:35282 | URL:http://secunia.com/advisories/35282",Assigned (20090601),"None (candidate not yet proposed)",
218| [CVE-2009-1928,Candidate,"Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2] Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2
219| [CVE-2009-2123,Candidate,"Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php] and the (3) id parameter to (b) show_bug.php and (c) show_activity.php. NOTE: it was later reported that vector 3c also affects 1.2.2.","MILW0RM:8953 | URL:http://www.milw0rm.com/exploits/8953 | MILW0RM:9342 | URL:http://www.milw0rm.com/exploits/9342 | SECUNIA:35486 | URL:http://secunia.com/advisories/35486",Assigned (20090619),"None (candidate not yet proposed)",
220| [CVE-2009-2156,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Title field to requests.php, related to viewrequests.php] and (2) the Torrent Name field to torrents-upload.php, related to the logging of torrent uploads
221| [CVE-2009-2160,Candidate,"TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function] and allows remote attackers to (2) obtain other potentially sensitive information via a direct request to check.php.","BUGTRAQ:20090615 [waraxe-2009-SA#074] - Multiple Vulnerabilities in TorrentTrader Classic 1.09 | URL:http://www.securityfocus.com/archive/1/archive/1/504294/100/0/threaded | MILW0RM:8958 | URL:http://www.milw0rm.com/exploits/8958 | MISC:http://www.waraxe.us/advisory-74.html | BID:35369 | URL:http://www.securityfocus.com/bid/35369 | SECUNIA:35456 | URL:http://secunia.com/advisories/35456 | XF:torrenttrader-check-info-disclosure(51148) | URL:http://xforce.iss.net/xforce/xfdb/51148 | XF:torrenttrader-phpinfo-info-disclosure(51149) | URL:http://xforce.iss.net/xforce/xfdb/51149",Assigned (20090622),"None (candidate not yet proposed)",
222| [CVE-2009-2185,Candidate,"The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2] and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string.","CONFIRM:http://download.strongswan.org/CHANGES2.txt | CONFIRM:http://download.strongswan.org/CHANGES4.txt | CONFIRM:http://download.strongswan.org/CHANGES42.txt | CONFIRM:http://up2date.astaro.com/2009/07/up2date_7404_released.html | CONFIRM:http://www.ingate.com/Relnote.php?ver=481 | DEBIAN:DSA-1898 | URL:http://www.debian.org/security/2009/dsa-1898 | DEBIAN:DSA-1899 | URL:http://www.debian.org/security/2009/dsa-1899 | FEDORA:FEDORA-2009-7423 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00264.html | FEDORA:FEDORA-2009-7478 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00337.html | REDHAT:RHSA-2009:1138 | URL:http://www.redhat.com/support/errata/RHSA-2009-1138.html | BID:35452 | URL:http://www.securityfocus.com/bid/35452 | OVAL:oval:org.mitre.oval:def:11079 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11079 | SECTRACK:1022428 | URL:http://www.securitytracker.com/id?1022428 | SECUNIA:35522 | URL:http://secunia.com/advisories/35522 | SECUNIA:35698 | URL:http://secunia.com/advisories/35698 | SECUNIA:35740 | URL:http://secunia.com/advisories/35740 | SECUNIA:35804 | URL:http://secunia.com/advisories/35804 | SECUNIA:36922 | URL:http://secunia.com/advisories/36922 | SECUNIA:36950 | URL:http://secunia.com/advisories/36950 | SECUNIA:37504 | URL:http://secunia.com/advisories/37504 | VUPEN:ADV-2009-1639 | URL:http://www.vupen.com/english/advisories/2009/1639 | VUPEN:ADV-2009-1829 | URL:http://www.vupen.com/english/advisories/2009/1829 | VUPEN:ADV-2009-3354 | URL:http://www.vupen.com/english/advisories/2009/3354 | VUPEN:ADV-2009-1706 | URL:http://www.vupen.com/english/advisories/2009/1706",Assigned (20090624),"None (candidate not yet proposed)",
223| [CVE-2009-2220,Candidate,"Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and possibly execute arbitrary files via directory traversal sequences in the template_path parameter to (1) masthead.inc.php, (2) toppanel.inc.php, and (3) contact.inc.php in templates/mytribiqsite/tribiq-CL-9000/includes] and the use_template_family parameter to (4) templates/mytribiqsite/tribiq-CL-9000/includes/nlarlist_content.inc.php. NOTE: the tribal-GPL-1066/includes/header.inc.php vector is already covered by CVE-2008-4894.","MILW0RM:9012 | URL:http://www.milw0rm.com/exploits/9012 | BID:35484 | URL:http://www.securityfocus.com/bid/35484 | SECUNIA:35535 | URL:http://secunia.com/advisories/35535",Assigned (20090626),"None (candidate not yet proposed)",
224| [CVE-2009-2333,Candidate,"Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the menu parameter to admin/admin_menu.php, and the id parameter to (2) index.php and (3) admin/admin_edit.php] and (4) delete arbitrary local files via a .. (dot dot) in the id parameter to admin/admin_delete.php. NOTE: vector 2 can be leveraged for static code injection by sending a crafted menu parameter to admin/admin_menu.php, and then sending an id=../menu.csv request to index.php.","MILW0RM:9069 | URL:http://www.milw0rm.com/exploits/9069 | OSVDB:55666 | URL:http://osvdb.org/55666 | OSVDB:55667 | URL:http://osvdb.org/55667 | OSVDB:55668 | URL:http://osvdb.org/55668 | OSVDB:55669 | URL:http://osvdb.org/55669",Assigned (20090705),"None (candidate not yet proposed)",
225| [CVE-2009-2428,Candidate,"Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL commands via the (1) userid parameter to suchauftraege_user.php and the (2) descr parameter to vote.php] and other unspecified vectors.","MISC:http://packetstorm.linuxsecurity.com/0907-exploits/tausch-sql.txt | SECUNIA:35725 | URL:http://secunia.com/advisories/35725 | VUPEN:ADV-2009-1823 | URL:http://www.vupen.com/english/advisories/2009/1823",Assigned (20090710),"None (candidate not yet proposed)",
226| [CVE-2009-2439,Candidate,"Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party] it is not associated with alibaba.com or the Alibaba Group.","MISC:http://packetstormsecurity.org/0907-exploits/alibabaclone-sql.txt | SECUNIA:35741 | URL:http://secunia.com/advisories/35741 | VUPEN:ADV-2009-1838 | URL:http://www.vupen.com/english/advisories/2009/1838",Assigned (20090713),"None (candidate not yet proposed)",
227| [CVE-2009-3017,Candidate,"Orca Browser 1.2 build 5 does not properly block data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header, (3) injecting a Location header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header] and does not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (5) injecting a Location HTTP response header or (6) specifying the content of a Location HTTP response header.","BUGTRAQ:20090828 Cross-Site Scripting vulnerability in Mozilla, Firefox, SeaMonkey, Orca Browser and Maxthon | URL:http://www.securityfocus.com/archive/1/archive/1/506163/100/0/threaded | MISC:http://websecurity.com.ua/3386/ | XF:orca-browser-data-xss(53002) | URL:http://xforce.iss.net/xforce/xfdb/53002",Assigned (20090831),"None (candidate not yet proposed)",
228| [CVE-2009-3018,Candidate,"Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header] does not properly block data: URIs in Location headers in HTTP responses, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (5) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (6) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header
229| [CVE-2009-3192,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in index.php in LinkorCMS 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the searchstr parameter in a search action] or the (2) nikname, (3) realname, (4) homepage, or (5) city parameter in a registration action.","MISC:http://packetstormsecurity.org/0908-exploits/linkorcms-xss.txt | SECUNIA:36487 | URL:http://secunia.com/advisories/36487",Assigned (20090915),"None (candidate not yet proposed)",
230| [CVE-2009-3508,Candidate,"Multiple directory traversal vulnerabilities in MUJE CMS 1.0.4.34 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) _class parameter to admin.php and the (2) url parameter to install/install.php] and allow remote authenticated administrators to read arbitrary files via a .. (dot dot) in the (3) _htmlfile parameter to admin.php.","MILW0RM:9314 | URL:http://www.milw0rm.com/exploits/9314 | SECUNIA:36079 | URL:http://secunia.com/advisories/36079",Assigned (20091001),"None (candidate not yet proposed)",
231| [CVE-2009-3514,Candidate,"Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php] and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php.","MILW0RM:9312 | URL:http://www.milw0rm.com/exploits/9312",Assigned (20091001),"None (candidate not yet proposed)",
232| [CVE-2009-3748,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1) FileName, (2) IsolatedMessageID, (3) ServerName, (4) Dictionary, (5) Scoring, and (6) MessagePart parameters to web/msgList/viewmsg/actions/msgAnalyse.asp] the (7) Queue, (8) FileName, (9) IsolatedMessageID, and (10) ServerName parameters to actions/msgForwardToRiskFilter.asp and viewHeaders.asp in web/msgList/viewmsg/
233| [CVE-2009-3803,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags] the status_message parameter to (6) forum.php, (7) discussion.php, (8) guestbook.php, (9) blog.php, (10) news.php, (11) srv_updates.php, (12) srv_backups.php, (13) srv_twist_prevention.php, (14) srv_tags.php, (15) srv_tags_reindex.php, (16) google_sitemap.php, (17) sitemap_history.php, (18) srv_options.php, (19) locales.php and (20) plugins_wizard.php in _admin/
234| [CVE-2009-4046,Candidate,"Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x before 2.2 RC allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) bank_accounts.php, (2) currencies.php, (3) exchange_rates.php, (4) gl_account_types.php, and (5) gl_accounts.php in gl/manage/] and (6) audit_trail_db.inc, (7) comments_db.inc, (8) inventory_db.inc, (9) manufacturing_db.inc, and (10) references_db.inc in includes/db/.","CONFIRM:http://frontaccounting.net/wb3/pages/posts/release-2.2-rc104.php | CONFIRM:http://sourceforge.net/projects/frontaccounting/files/FrontAccounting-2/2.2%20RC/frontaccount-2.2RC.tar.gz/download | VUPEN:ADV-2009-3223 | URL:http://www.vupen.com/english/advisories/2009/3223",Assigned (20091120),"None (candidate not yet proposed)",
235| [CVE-2009-4088,Candidate,"Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php] and include and execute arbitrary local files via the (3) group parameter to upload.php.","MISC:http://packetstormsecurity.org/0911-exploits/Telepark-fixes-nov09-2.txt | EXPLOIT-DB:9483 | URL:http://www.exploit-db.com/exploits/9483 | CONFIRM:http://blog.telepark.com/telepark-web-software/2009/11/09/telepark-wiki-security-fixes/ | OSVDB:60216 | URL:http://www.osvdb.org/60216 | OSVDB:60217 | URL:http://www.osvdb.org/60217 | OSVDB:60218 | URL:http://www.osvdb.org/60218 | SECUNIA:37391 | URL:http://secunia.com/advisories/37391 | XF:teleparkwiki-multiple-file-include(54327) | URL:http://xforce.iss.net/xforce/xfdb/54327",Assigned (20091127),"None (candidate not yet proposed)",
236| [CVE-2009-4385,Candidate,"Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the authentication of arbitrary users for requests that delete polls via the delete_poll action to index.php] and hijack the authentication of administrators for requests that (2) delete users via the manage action to admin.php, or (3) send arbitrary email to arbitrary users in the email action to admin.php.","MISC:http://packetstormsecurity.org/0912-exploits/ezpollhoster-xssxsrf.txt | EXPLOIT-DB:10439 | URL:http://www.exploit-db.com/exploits/10439 | SECUNIA:37716 | URL:http://secunia.com/advisories/37716 | VUPEN:ADV-2009-3529 | URL:http://www.vupen.com/english/advisories/2009/3529",Assigned (20091222),"None (candidate not yet proposed)",
237| [CVE-2009-4433,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (a) 5 or (b) 9 field in a post action to ticket_function.php, reachable through ticket_submit.php and index.php] (c) the which parameter to function.php, or (d) the which parameter to index.php, related to knowledgebase_list.php. NOTE: some of these details are obtained from third party information.","MISC:http://packetstormsecurity.org/0912-exploits/isupport-lfixss.txt | EXPLOIT-DB:10478 | URL:http://www.exploit-db.com/exploits/10478 | BID:37380 | URL:http://www.securityfocus.com/bid/37380 | OSVDB:61109 | URL:http://www.osvdb.org/61109 | OSVDB:61111 | URL:http://www.osvdb.org/61111 | OSVDB:61112 | URL:http://www.osvdb.org/61112 | SECUNIA:37726 | URL:http://secunia.com/advisories/37726 | XF:isupport-index-function-xss(54859) | URL:http://xforce.iss.net/xforce/xfdb/54859 | XF:isupport-ticketfunction-xss(54858) | URL:http://xforce.iss.net/xforce/xfdb/54858",Assigned (20091228),"None (candidate not yet proposed)",
238| [CVE-2009-4537,Candidate,"drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters] or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.","MLIST:[linux-netdev] 20091228 [PATCH RFC] r8169: straighten out overlength frame detection | URL:http://marc.info/?l=linux-netdev&m=126202972828626&w=2 | MLIST:[oss-security] 20091228 CVE requests - kernel security regressions for CVE-2009-1385/and -1389 | URL:http://www.openwall.com/lists/oss-security/2009/12/28/1 | MLIST:[oss-security] 20091229 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389 | URL:http://www.openwall.com/lists/oss-security/2009/12/29/2 | MLIST:[oss-security] 20091231 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389 | URL:http://www.openwall.com/lists/oss-security/2009/12/31/1 | MISC:http://blog.c22.cc/2009/12/27/26c3-cat-procsysnetipv4fuckups/ | MISC:http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html | MISC:http://twitter.com/dakami/statuses/7104238406 | CONFIRM:http://marc.info/?t=126202986900002&r=1&w=2 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=550907 | DEBIAN:DSA-2053 | URL:http://www.debian.org/security/2010/dsa-2053 | FEDORA:FEDORA-2010-1787 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html | REDHAT:RHSA-2010:0019 | URL:http://www.redhat.com/support/errata/RHSA-2010-0019.html | REDHAT:RHSA-2010:0020 | URL:http://www.redhat.com/support/errata/RHSA-2010-0020.html | REDHAT:RHSA-2010:0041 | URL:http://www.redhat.com/support/errata/RHSA-2010-0041.html | REDHAT:RHSA-2010:0095 | URL:https://rhn.redhat.com/errata/RHSA-2010-0095.html | REDHAT:RHSA-2010:0111 | URL:http://www.redhat.com/support/errata/RHSA-2010-0111.html | REDHAT:RHSA-2010:0053 | URL:http://www.redhat.com/support/errata/RHSA-2010-0053.html | SUSE:SUSE-SA:2010:023 | URL:http://www.novell.com/linux/security/advisories/2010_23_kernel.html | SUSE:SUSE-SA:2010:031 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html | BID:37521 | URL:http://www.securityfocus.com/bid/37521 | OVAL:oval:org.mitre.oval:def:7443 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7443 | OVAL:oval:org.mitre.oval:def:9439 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9439 | SECTRACK:1023419 | URL:http://securitytracker.com/id?1023419 | SECUNIA:38031 | URL:http://secunia.com/advisories/38031 | SECUNIA:38610 | URL:http://secunia.com/advisories/38610 | SECUNIA:39742 | URL:http://secunia.com/advisories/39742 | SECUNIA:39830 | URL:http://secunia.com/advisories/39830 | SECUNIA:40645 | URL:http://secunia.com/advisories/40645 | VUPEN:ADV-2010-1857 | URL:http://www.vupen.com/english/advisories/2010/1857 | XF:kernel-r8169-dos(55647) | URL:http://xforce.iss.net/xforce/xfdb/55647",Assigned (20091231),"None (candidate not yet proposed)",
239| [CVE-2009-4908,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2) commentEmail, (3) commentWeb, or (4) commentText parameter to article.php] and allow remote authenticated administrators to inject arbitrary web script or HTML via the (5) article_id or (6) title parameter to admin/write.php, the (7) category_id or (8) category_name parameter to admin/groups.php, the (9) blogroll_id or (10) title parameter to admin/blogroll.php, or the (11) blog_name or (12) tag_line parameter to admin/settings.php.","MISC:http://packetstormsecurity.org/0912-exploits/oblog-xssxsrf.txt | OSVDB:60906 | URL:http://osvdb.org/60906 | SECUNIA:37661 | URL:http://secunia.com/advisories/37661 | XF:oblog-article-xss(54713) | URL:http://xforce.iss.net/xforce/xfdb/54713",Assigned (20100625),"None (candidate not yet proposed)",
240| [CVE-2010-0014,Candidate,"System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation that has any user's Kerberos ticket-granting ticket (TGT)] and might allow remote attackers to bypass intended access restrictions via vectors involving an arbitrary password in conjunction with a valid TGT.","CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=553233 | CONFIRM:https://fedorahosted.org/sssd/wiki/Releases/Notes-1.0.1 | BID:37747 | URL:http://www.securityfocus.com/bid/37747 | SECUNIA:38160 | URL:http://secunia.com/advisories/38160",Assigned (20091214),"None (candidate not yet proposed)",
241| [CVE-2010-0108,Candidate,"Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4] and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.","BUGTRAQ:20100219 [DSECRG-09-039] Symantec Antivirus 10.0 ActiveX - buffer Overflow. | URL:http://www.securityfocus.com/archive/1/archive/1/509681/100/0/threaded | MISC:http://dsecrg.com/pages/vul/show.php?id=139 | CONFIRM:http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100217_02 | BID:38222 | URL:http://www.securityfocus.com/bid/38222 | SECUNIA:38651 | URL:http://secunia.com/advisories/38651 | VUPEN:ADV-2010-0412 | URL:http://www.vupen.com/english/advisories/2010/0412 | XF:scp-cliproxy-activex-bo(56355) | URL:http://xforce.iss.net/xforce/xfdb/56355",Assigned (20091231),"None (candidate not yet proposed)",
242| [CVE-2010-0820,Candidate,"Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2] Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server 2003 SP2
243| [CVE-2010-0988,Candidate,"Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary PHP code via vectors related to improper handling of login failures by includes/login.php] and allow remote authenticated users to write to arbitrary files and execute arbitrary PHP code via vectors involving the (2) filename and (3) block parameters to view.php.","BUGTRAQ:20100324 Secunia Research: Pulse CMS Arbitrary File Writing Vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/510299/100/0/threaded | BUGTRAQ:20100324 Secunia Research: Pulse CMS login.php Arbitrary File Writing Vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/510300/100/0/threaded | MISC:http://secunia.com/secunia_research/2010-45/ | MISC:http://secunia.com/secunia_research/2010-51/ | BID:38956 | URL:http://www.securityfocus.com/bid/38956 | OSVDB:63166 | URL:http://www.osvdb.org/63166 | OSVDB:63168 | URL:http://www.osvdb.org/63168 | SECUNIA:39011 | URL:http://secunia.com/advisories/39011",Assigned (20100318),"None (candidate not yet proposed)",
244| [CVE-2010-1217,Candidate,"Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator] however, the exploit URL suggests that Form Creator is affected.","EXPLOIT-DB:11814 | URL:http://www.exploit-db.com/exploits/11814 | MISC:http://www.packetstormsecurity.org/1003-exploits/joomlajetooltip-lfi.txt | BID:38866 | URL:http://www.securityfocus.com/bid/38866 | OSVDB:63120 | URL:http://osvdb.org/63120 | SECUNIA:39063 | URL:http://secunia.com/advisories/39063",Assigned (20100330),"None (candidate not yet proposed)",
245| [CVE-2010-1326,Candidate,"perms.cpp in March Hare Software CVSNT 2.0.58, 2.5.01, 2.5.02, 2.5.03 before build 3736, 2.5.04 before build 2862] CVS Suite 2.5.03, 2008 before build 3736, and 2009 before 3729 allows remote attackers to bypass the permissions check, modify arbitrary modules and directories within CVSROOT, and execute arbitrary code via a crafted branch name ACL, possibly related to incorrect inheritance.","MISC:http://customer.march-hare.com/webtools/bugzilla/attachment.cgi?tt=1&id=1790&action=view | CONFIRM:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=593884 | CONFIRM:http://march-hare.com/cvspro/vuln.htm | DEBIAN:DSA-2108 | URL:http://www.debian.org/security/2010/dsa-2108 | SECUNIA:41345 | URL:http://secunia.com/advisories/41345 | SECUNIA:41358 | URL:http://secunia.com/advisories/41358 | VUPEN:ADV-2010-2350 | URL:http://www.vupen.com/english/advisories/2010/2350",Assigned (20100408),"None (candidate not yet proposed)",
246| [CVE-2010-1517,Candidate,"The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving the dl method] and (2) download arbitrary programs onto a client system via vectors involving the SetDLInfo method in conjunction with the Bdl method.","MISC:http://secunia.com/secunia_research/2010-85/ | SECUNIA:40161 | URL:http://secunia.com/advisories/40161",Assigned (20100426),"None (candidate not yet proposed)",
247| [CVE-2010-1916,Candidate,"The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backend_config_secret_key_location and backend_config_hash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the ""Deprecated config passing"" feature] or (2) crafted backend_data and backend_data[key_location] variables, which are not properly handled by the xinha_read_passed_data function. NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.","MISC:http://www.php-security.org/2010/05/10/mops-2010-019-serendipity-wysiwyg-editor-plugin-configuration-injection-vulnerability/index.html | MISC:http://www.php-security.org/2010/05/10/mops-2010-020-xinha-wysiwyg-plugin-configuration-injection-vulnerability/index.html | CONFIRM:http://trac.xinha.org/ticket/1518 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=591701 | FEDORA:FEDORA-2010-9320 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042577.html | BID:40033 | URL:http://www.securityfocus.com/bid/40033 | SECUNIA:39782 | URL:http://secunia.com/advisories/39782 | SECUNIA:40124 | URL:http://secunia.com/advisories/40124 | VUPEN:ADV-2010-1401 | URL:http://www.vupen.com/english/advisories/2010/1401",Assigned (20100511),"None (candidate not yet proposed)",
248| [CVE-2010-2123,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) address, (3) city, (4) provstate (aka state), (5) phone, or (6) taxid parameter in a stormorganization action to index.php] the (7) name parameter in a stormperson action to index.php
249| [CVE-2010-2503,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) redirects, aka SPL-31067] (2) unspecified ""user->user or user->admin"" vectors, aka SPL-31084
250| [CVE-2010-2536,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in rekonq 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a URL associated with a nonexistent domain name, related to webpage.cpp, aka a ""universal XSS"" issue] (2) unspecified vectors related to webview.cpp
251| [CVE-2010-2545,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via (1) the name element in an XML template to templates_import.php] and allow remote authenticated administrators to inject arbitrary web script or HTML via vectors related to (2) cdef.php, (3) data_input.php, (4) data_queries.php, (5) data_sources.php, (6) data_templates.php, (7) gprint_presets.php, (8) graph.php, (9) graphs_new.php, (10) graphs.php, (11) graph_templates_inputs.php, (12) graph_templates_items.php, (13) graph_templates.php, (14) graph_view.php, (15) host.php, (16) host_templates.php, (17) lib/functions.php, (18) lib/html_form.php, (19) lib/html_form_template.php, (20) lib/html.php, (21) lib/html_tree.php, (22) lib/rrd.php, (23) rra.php, (24) tree.php, and (25) user_admin.php.","MLIST:[oss-security] 20100722 Cacti XSS fixes in 0.8.7g | URL:http://marc.info/?l=oss-security&m=127978954522586&w=2 | MLIST:[oss-security] 20100726 Re: Cacti XSS fixes in 0.8.7g | URL:http://marc.info/?l=oss-security&m=128017203704299&w=2 | CONFIRM:http://cacti.net/release_notes_0_8_7g.php | CONFIRM:http://svn.cacti.net/viewvc?view=rev&revision=6037 | CONFIRM:http://svn.cacti.net/viewvc?view=rev&revision=6038 | CONFIRM:http://svn.cacti.net/viewvc?view=rev&revision=6041 | CONFIRM:http://svn.cacti.net/viewvc?view=rev&revision=6042 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=459229 | MANDRIVA:MDVSA-2010:160 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:160 | REDHAT:RHSA-2010:0635 | URL:https://rhn.redhat.com/errata/RHSA-2010-0635.html | BID:42575 | URL:http://www.securityfocus.com/bid/42575 | SECUNIA:41041 | URL:http://secunia.com/advisories/41041 | VUPEN:ADV-2010-2132 | URL:http://www.vupen.com/english/advisories/2010/2132 | XF:cacti-templatesimport-xss(61227) | URL:http://xforce.iss.net/xforce/xfdb/61227",Assigned (20100630),"None (candidate not yet proposed)",
252| [CVE-2010-2625,Candidate,"Unspecified vulnerability in the Client Service for DPM in Hitachi ServerConductor / Deployment Manager 01-00, 01-01, and 06-00 through 06-00-/A] ServerConductor / Deployment Manager Standard Edition and Enterprise Edition 07-50 through 07-55, and 07-57 through 07-59
253| [CVE-2010-3023,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) category[description] parameter to user/main/update_category, which is not properly handled by _app/views/categories/index.html.erb] and the (2) setting[site_title] parameter to user/main/update_settings, which is not properly handled by _app/views/settings/_list_settings.rhtml.","BUGTRAQ:20100805 XSS vulnerability in DiamondList | URL:http://www.securityfocus.com/archive/1/archive/1/512897/100/0/threaded | BUGTRAQ:20100805 XSS vulnerability in DiamondList | URL:http://www.securityfocus.com/archive/1/512892 | MISC:http://packetstormsecurity.org/1008-exploits/diamondlist-xssxsrf.txt | MISC:http://www.htbridge.ch/advisory/xss_vulnerability_in_diamondlist.html | MISC:http://www.htbridge.ch/advisory/xss_vulnerability_in_diamondlist_1.html | CONFIRM:http://dev.hulihanapplications.com/issues/show/211 | CONFIRM:http://dev.hulihanapplications.com/issues/show/213 | BID:42252 | URL:http://www.securityfocus.com/bid/42252 | SECUNIA:40873 | URL:http://secunia.com/advisories/40873 | VUPEN:ADV-2010-2025 | URL:http://www.vupen.com/english/advisories/2010/2025",Assigned (20100816),"None (candidate not yet proposed)",
254| [CVE-2010-3025,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) excerpt parameter to application/modules/admin/controllers/posts.php, as reachable by admin/posts/edit] and the (2) content parameter to application/modules/admin/controllers/pages.php, as reachable by admin/posts/edit.","BUGTRAQ:20100805 XSS vulnerability in Open Blog | URL:http://www.securityfocus.com/archive/1/archive/1/512895/100/0/threaded | BUGTRAQ:20100805 XSS vulnerability in Open blog | URL:http://www.securityfocus.com/archive/1/archive/1/512901/100/0/threaded | MISC:http://packetstormsecurity.org/1008-exploits/openblog-xssxsrf.txt | MISC:http://www.htbridge.ch/advisory/xss_vulnerability_in_open_blog.html | MISC:http://www.htbridge.ch/advisory/xss_vulnerability_in_open_blog_1.html | BID:42255 | URL:http://www.securityfocus.com/bid/42255 | SECUNIA:40876 | URL:http://secunia.com/advisories/40876 | XF:openblog-users-xss(60942) | URL:http://xforce.iss.net/xforce/xfdb/60942",Assigned (20100816),"None (candidate not yet proposed)",
255| [CVE-2010-3105,Candidate,"The PluginGetDriverFile function in Novell iPrint Client before 5.44 interprets an uninitialized memory location as a pointer value, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","BID:42576 | URL:http://www.securityfocus.com/bid/42576 | OVAL:oval:org.mitre.oval:def:11817 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11817 | SECUNIA:40805 | URL:http://secunia.com/advisories/40805",Assigned (20100823),"None (candidate not yet proposed)",
256| [CVE-2010-3191,Candidate,"Untrusted search path vulnerability in Adobe Captivate 5.0.0.596, and possibly other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .cptx file. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","OVAL:oval:org.mitre.oval:def:7470 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7470 | SECUNIA:41233 | URL:http://secunia.com/advisories/41233",Assigned (20100831),"None (candidate not yet proposed)",
257| [CVE-2010-4073,Candidate,"The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_msgctl, and (3) compat_sys_shmctl functions in ipc/compat.c] and the (4) compat_sys_mq_open and (5) compat_sys_mq_getsetattr functions in ipc/compat_mq.c.","BUGTRAQ:20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console | URL:http://www.securityfocus.com/archive/1/archive/1/520102/100/0/threaded | MLIST:[linux-kernel] 20101006 [PATCH v3] IPC: Initialize structure memory to zero for compat functions | URL:http://lkml.org/lkml/2010/10/6/492 | MLIST:[oss-security] 20101006 Re: CVE request: multiple kernel stack memory disclosures | URL:http://www.openwall.com/lists/oss-security/2010/10/07/1 | MLIST:[oss-security] 20101025 Re: CVE request: multiple kernel stack memory disclosures | URL:http://www.openwall.com/lists/oss-security/2010/10/25/3 | CONFIRM:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git
258| [CVE-2010-5282,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort parameters in a browse action to livelink/livelink] and the (3) nodeid, (4) setctx, and (5) support parameters to livelinkdav/nodes/OOB_DAVWindow.html.","FULLDISC:20100922 OpenText LiveLink 9.7.1 multiple vulnerabilities (CSRF, XSS) | URL:http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0359.html | MISC:http://packetstormsecurity.org/1009-exploits/opentext-xsrfxss.txt | OSVDB:68256 | URL:http://www.osvdb.org/68256 | OSVDB:68257 | URL:http://www.osvdb.org/68257 | SECUNIA:41553 | URL:http://secunia.com/advisories/41553 | XF:ecm-multiple-xss(62056) | URL:http://xforce.iss.net/xforce/xfdb/62056",Assigned (20121126),"None (candidate not yet proposed)",
259| [CVE-2011-0533,Candidate,"Cross-site scripting (XSS) vulnerability in Apache Continuum 1.1 through 1.2.3.1, 1.3.6, and 1.4.0 Beta] and Archiva 1.3.0 through 1.3.3 and 1.0 through 1.22 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to the autoIncludeParameters setting for the extremecomponents table.","BUGTRAQ:20110210 [SECURITY] CVE-2011-0533: Apache Continuum cross-site scripting vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/516342/100/0/threaded | BUGTRAQ:20110216 [SECURITY] CVE-2011-0533: Apache Archiva cross-site scripting vulnerability | URL:http://www.securityfocus.com/archive/1/archive/1/516474/100/0/threaded | FULLDISC:20110211 [SECURITY] CVE-2011-0533: Apache Continuum cross-site scripting vulnerability | URL:http://seclists.org/fulldisclosure/2011/Feb/236 | MLIST:[continuum-users] 20110210 [SECURITY] CVE-2011-0533: Apache Continuum cross-site scripting vulnerability | URL:http://mail-archives.apache.org/mod_mbox/continuum-users/201102.mbox/%3C981C0A79-5B7B-4053-84CC-3217870BE360@apache.org%3E | CONFIRM:http://continuum.apache.org/security.html | CONFIRM:http://jira.codehaus.org/browse/CONTINUUM-2604 | CONFIRM:http://svn.apache.org/viewvc?view=revision&revision=1066053 | CONFIRM:http://svn.apache.org/viewvc?view=revision&revision=1066056 | BID:46311 | URL:http://www.securityfocus.com/bid/46311 | OSVDB:70925 | URL:http://osvdb.org/70925 | OVAL:oval:org.mitre.oval:def:12581 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12581 | SECTRACK:1025065 | URL:http://securitytracker.com/id?1025065 | SECUNIA:43261 | URL:http://secunia.com/advisories/43261 | SECUNIA:43334 | URL:http://secunia.com/advisories/43334 | SREASON:8091 | URL:http://securityreason.com/securityalert/8091 | VUPEN:ADV-2011-0373 | URL:http://www.vupen.com/english/advisories/2011/0373 | VUPEN:ADV-2011-0426 | URL:http://www.vupen.com/english/advisories/2011/0426 | XF:continuum-unspec-xss(65343) | URL:http://xforce.iss.net/xforce/xfdb/65343",Assigned (20110120),"None (candidate not yet proposed)",
260| [CVE-2011-0785,Candidate,"Unspecified vulnerability in the Oracle Help component in Oracle Database Server 11.1.0.7, 11.2.0.1, 11.2.0.2, 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, and 10.1.0.5] and Oracle Fusion Middleware 11.1.1.2.0, 11.1.1.3.0, and 11.1.1.4.0 allows remote attackers to affect integrity via unknown vectors.","CONFIRM:http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html",Assigned (20110204),"None (candidate not yet proposed)",
261| [CVE-2011-0975,Candidate,"Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10] Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10
262| [CVE-2011-1546,Candidate,"Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to execute arbitrary SQL commands via the s parameter to (1) a_viewusers.php or (2) keysearch.php] and allow remote authenticated administrators to execute arbitrary SQL commands via the (3) id or (4) start parameter to pending.php, or the (5) aid parameter to a_authordetails.php. NOTE: some of these details are obtained from third party information.","BUGTRAQ:20110330 'Andy's PHP Knowledgebase' SQL Injection Vulnerability (CVE-2011-1546) | URL:http://www.securityfocus.com/archive/1/archive/1/517261/100/0/threaded | EXPLOIT-DB:17084 | URL:http://www.exploit-db.com/exploits/17084/ | MISC:http://www.uncompiled.com/2011/03/cve-2011-1546/ | CONFIRM:http://aphpkb.blogspot.com/2011/03/this-release-includes-security-fixes.html | BID:47097 | URL:http://www.securityfocus.com/bid/47097 | SECUNIA:34476 | URL:http://secunia.com/advisories/34476 | SREASON:8168 | URL:http://securityreason.com/securityalert/8168 | SREASON:8172 | URL:http://securityreason.com/securityalert/8172 | VUPEN:ADV-2011-0802 | URL:http://www.vupen.com/english/advisories/2011/0802 | XF:aphpkb-aviewusers-sql-injection(66500) | URL:http://xforce.iss.net/xforce/xfdb/66500",Assigned (20110329),"None (candidate not yet proposed)",
263| [CVE-2011-2710,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php] and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5.","MLIST:[oss-security] 20110722 CVE Request: Joomla! 1.7.0-RC and lower | Cross Site Scripting Vulnerabilities | URL:http://www.openwall.com/lists/oss-security/2011/07/22/1 | MLIST:[oss-security] 20110722 Re: CVE Request: Joomla! 1.7.0-RC and lower | Cross Site Scripting Vulnerabilities | URL:http://www.openwall.com/lists/oss-security/2011/07/22/5 | MLIST:[oss-security] 20111016 Duplicate CVE assigned: CVE-2011-2708 CVE-2011-2710 | URL:http://www.openwall.com/lists/oss-security/2011/10/16/1 | MLIST:[oss-security] 20111121 Re: Fwd: XSS vulnerability in Joomla 1.6.3 - CVE-2011-2710 / CVE-2011-2708 issue | URL:http://www.openwall.com/lists/oss-security/2011/11/21/27 | MISC:http://yehg.net/lab/pr0js/advisories/joomla/core/[joomla_1.7.0-rc]_cross_site_scripting(XSS) | CONFIRM:http://developer.joomla.org/security/news/357-20110701-xss-vulnerability.html",Assigned (20110711),"None (candidate not yet proposed)",
264| [CVE-2011-2738,Candidate,"Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1] and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for Alcatel-Lucent 5620 SAM EMS (Ionix ASAM) 3.2.0.2 and earlier, IP Management Suite (Ionix IP) 8.1.1.1 and earlier, and other Ionix products
265| [CVE-2011-3209,Candidate,"The div_long_long_rem implementation in include/asm-x86/div64.h in the Linux kernel before 2.6.26 on the x86 platform allows local users to cause a denial of service (Divide Error Fault and panic) via a clock_gettime system call.","MLIST:[oss-security] 20111024 kernel] CVE-2011-2942 and CVE-2011-3209 | URL:http://www.openwall.com/lists/oss-security/2011/10/24/3 | CONFIRM:http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26 | CONFIRM:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git
266| [CVE-2011-4340,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author privileges to inject arbitrary web script or HTML via (1) the profile parameter to extensions/profiledevkit/content/content.profile.php, as demonstrated via requests to (a) the default URI, (b) about/, or (c) drafts/] or (2) the filter parameter in symphony/lib/core/class.symphony.php, as demonstrated via requests to (d) symphony/publish/comments or (e) symphony/publish/images. NOTE: some of these details are obtained from third party information.","BUGTRAQ:20111101 XSS and SQL Injection Vulnerabilities on Symphony CMS 2.2.3 | URL:http://seclists.org/bugtraq/2011/Nov/8 | MLIST:[oss-security] 20111122 Re: CVE-request: Symphony CMS Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (NS-11-008) | URL:http://www.openwall.com/lists/oss-security/2011/11/22/9 | MISC:http://packetstormsecurity.org/files/view/106493/symphonycms-sqlxss.txt | MISC:http://www.mavitunasecurity.com/xss-and-sql-injection-vulnerabilities-in-symphony-cms/ | CONFIRM:http://symphony-cms.com/download/releases/version/2.2.4/ | OSVDB:76882 | URL:http://www.osvdb.org/76882 | OSVDB:76883 | URL:http://www.osvdb.org/76883 | SECUNIA:46663 | URL:http://secunia.com/advisories/46663 | XF:symphony-multiple-xss(71106) | URL:http://xforce.iss.net/xforce/xfdb/71106",Assigned (20111104),"None (candidate not yet proposed)",
267| [CVE-2011-5070,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject arbitrary web script or HTML via (1) the file name to incident_attachments.php] (2) unspecified vectors in link_add.php, possibly involving origref, linkref, linktype parameters, which are not properly handled in the clean_int function in lib/base.inc.php, or the redirect parameter, which is not properly handled in the html_redirect function in lib/html.inc.php
268| [CVE-2011-5111,Candidate,"Multiple SQL injection vulnerabilities in Kajian Website CMS Balitbang 3.x allow remote attackers to execute arbitrary SQL commands via the hal parameter to (1) the data module in alumni.php] or the (2) lih_buku, (3) artikel, (4) album, or (5) berita module in index.php.","MISC:http://packetstormsecurity.org/files/view/107254/cmsbalitbang-sql.txt | BID:50797 | URL:http://www.securityfocus.com/bid/50797 | XF:balitbang-hal-sql-injection(71466) | URL:http://xforce.iss.net/xforce/xfdb/71466",Assigned (20120823),"None (candidate not yet proposed)",
269| [CVE-2011-5177,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to the admins (2) blocks, (3) articles, or (4) suggest-category] or (5) sort parameter to the search page.","MISC:http://packetstormsecurity.org/files/view/107324/esyndicatpro-xss.txt | BID:50822 | URL:http://www.securityfocus.com/bid/50822 | XF:esyndicatpro-controller-xss(71485) | URL:http://xforce.iss.net/xforce/xfdb/71485",Assigned (20120919),"None (candidate not yet proposed)",
270| [CVE-2012-0829,Candidate,"Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication of operators for requests that insert cross-site scripting (XSS) sequences via the (1) address or (2) threadid parameters to operator/ban.php] or (3) geolinkparams, (4) title, or (5) chattitle parameters to operator/settings.php.","BUGTRAQ:20120130 Mibew messenger multiple XSS | URL:http://archives.neohapsis.com/archives/bugtraq/2012-01/0178.html | MLIST:[oss-security] 20120202 Re: XSS hiding CSRF (was: Re: Mibew messenger multiple XSS) | URL:http://www.openwall.com/lists/oss-security/2012/02/02/10 | MISC:http://www.codseq.it/advisories/mibew_messenger_multiple_xss | BID:51723 | URL:http://www.securityfocus.com/bid/51723 | SECUNIA:47787 | URL:http://secunia.com/advisories/47787 | XF:mibew-webinterface-csrf(72822) | URL:http://xforce.iss.net/xforce/xfdb/72822",Assigned (20120119),"None (candidate not yet proposed)",
271| [CVE-2012-1788,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in wonderdesk.cgi in WonderDesk SQL 4.14 allow remote attackers to inject arbitrary web script or HTML via the (1) cus_email parameter in a cust_lostpw action] or (2) help_name, (3) help_email, (4) help_website, or (5) help_example_url parameters in an hd_modify_record action.","MISC:http://packetstormsecurity.org/files/110224/WonderDesk-Cross-Site-Scripting.html | MISC:http://st2tea.blogspot.com/2012/02/wonderdesk-cross-site-scripting.html | BID:52193 | URL:http://www.securityfocus.com/bid/52193 | SECUNIA:48167 | URL:http://secunia.com/advisories/48167 | XF:wonderdesk-wonderdesk-xss(73502) | URL:http://xforce.iss.net/xforce/xfdb/73502",Assigned (20120319),"None (candidate not yet proposed)",
272| [CVE-2012-1845,Candidate,"Use-after-free vulnerability in Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the DEP and ASLR protection mechanisms, and execute arbitrary code, via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later] it was not identified by the researcher, who reportedly stated ""it really doesn't matter if it's third-party code.""","MISC:http://pwn2own.zerodayinitiative.com/status.html | MISC:http://twitter.com/vupen/statuses/177576000761237505 | MISC:http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/ | MISC:http://www.zdnet.com/blog/security/pwn2own-2012-google-chrome-browser-sandbox-first-to-fall/10588 | OVAL:oval:org.mitre.oval:def:14843 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14843",Assigned (20120322),"None (candidate not yet proposed)",
273| [CVE-2012-1846,Candidate,"Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later] it was not identified by the researcher, who reportedly stated ""it really doesn't matter if it's third-party code.""","MISC:http://pwn2own.zerodayinitiative.com/status.html | MISC:http://twitter.com/vupen/statuses/177576000761237505 | MISC:http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/ | MISC:http://www.zdnet.com/blog/security/pwn2own-2012-google-chrome-browser-sandbox-first-to-fall/10588 | OVAL:oval:org.mitre.oval:def:14940 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14940",Assigned (20120322),"None (candidate not yet proposed)",
274| [CVE-2012-4397,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) calendar displayname to part.choosecalendar.rowfields.php or (2) part.choosecalendar.rowfields.shared.php in apps/calendar/templates/] or (3) unspecified vectors to apps/contacts/lib/vcard.php.","MLIST:[oss-security] 20120810 ownCloud - matching CVEs to fix information and vice versa | URL:http://www.openwall.com/lists/oss-security/2012/08/11/1 | MLIST:[oss-security] 20120901 Re: CVE - ownCloud | URL:http://www.openwall.com/lists/oss-security/2012/09/02/2 | CONFIRM:http://owncloud.org/changelog/ | CONFIRM:https://github.com/owncloud/core/commit/00595351400523168e18a08e3ffa5c3b1e7c1f6e | CONFIRM:https://github.com/owncloud/core/commit/54a371700554ed21a5cb7db03126b6c95ae4cbd3",Assigned (20120821),"None (candidate not yet proposed)",
275| [CVE-2012-4771,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/] or (4) group parameter to admin/configuration/. NOTE: The f[accounts][fullname] and f[accounts][username] vectors are covered in CVE-2012-5452.","BUGTRAQ:20121017 Multiple vulnerabilities in Subrion CMS | URL:http://archives.neohapsis.com/archives/bugtraq/2012-10/0096.html | MISC:http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5105.php | MISC:https://www.htbridge.com/advisory/HTB23113 | MISC:http://packetstormsecurity.org/files/117460/Subrion-CMS-2.2.1-XSS-CSRF-SQL-Injection.html | CONFIRM:http://www.subrion.com/forums/announcements/934-subrion-2-2-3-open-source-cms-core-available.html | SECUNIA:51013 | URL:http://secunia.com/advisories/51013 | XF:subrioncms-id-group-xss(79468) | URL:http://xforce.iss.net/xforce/xfdb/79468",Assigned (20120906),"None (candidate not yet proposed)",
276| [CVE-2012-4820,Candidate,"Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier] as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager
277| [CVE-2012-4821,Candidate,"Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier] as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager
278| [CVE-2012-4822,Candidate,"Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier] as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager
279| [CVE-2012-4823,Candidate,"Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier] as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager
280| [CVE-2012-4891,Candidate,"Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. NOTE: the provenance of this information is unknown] the details are obtained solely from third party information.","EXPLOIT-DB:35933 | URL:http://www.exploit-db.com/exploits/35933 | MISC:http://packetstormsecurity.com/files/130169/ManageEngine-Firewall-Analyzer-8.0-Directory-Traversal-XSS.html | OSVDB:80874 | URL:http://osvdb.org/80874 | SECUNIA:48657 | URL:http://secunia.com/advisories/48657 | XF:manageengine-firewallanalyzer-xss(100551) | URL:http://xforce.iss.net/xforce/xfdb/100551",Assigned (20120910),"None (candidate not yet proposed)",
281| [CVE-2012-5167,Candidate,"Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/index_inline_editor_submit.php or (2) user/index_inline_editor_submit.php] or (3) id parameter to user/user_password.php.","BUGTRAQ:20121017 Multiple vulnerabilities in AContent | URL:http://archives.neohapsis.com/archives/bugtraq/2012-10/0095.html | MISC:https://www.htbridge.com/advisory/HTB23117 | CONFIRM:http://update.atutor.ca/acontent/patch/1_2/ | BID:56100 | URL:http://www.securityfocus.com/bid/56100 | OSVDB:86425 | URL:http://osvdb.org/86425 | OSVDB:86424 | URL:http://osvdb.org/86424 | SECUNIA:51014 | URL:http://secunia.com/advisories/51014 | SECUNIA:51034 | URL:http://secunia.com/advisories/51034 | XF:acontent-field-id-sql-injection(79460) | URL:http://xforce.iss.net/xforce/xfdb/79460 | XF:acontent-field-sql-injection(79459) | URL:http://xforce.iss.net/xforce/xfdb/79459",Assigned (20120926),"None (candidate not yet proposed)",
282| [CVE-2012-5893,Candidate,"Unrestricted file upload vulnerability in hava_upload.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading a file with a .php] .gif extension, then accessing it via a direct request to the file in tmp/files/.","MISC:http://packetstormsecurity.org/files/111358/Havalite-CMS-Shell-Upload-SQL-Injection-Disclosure.html | OSVDB:80768 | URL:http://osvdb.org/80768 | SECUNIA:48646 | URL:http://secunia.com/advisories/48646 | XF:havalite-upload-file-upload(74486) | URL:http://xforce.iss.net/xforce/xfdb/74486",Assigned (20121117),"None (candidate not yet proposed)",
283| [CVE-2012-6529,Candidate,"Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) galleryphoto.php or (2) gallery.php] or the roomid parameter to (3) room.php or (4) room2.php.","MISC:http://packetstormsecurity.org/files/view/108474/marinetcmsroomid-sql.txt | BID:51336 | URL:http://www.securityfocus.com/bid/51336 | XF:marinet-multiple-sql-injection(72272) | URL:http://xforce.iss.net/xforce/xfdb/72272",Assigned (20130130),"None (candidate not yet proposed)",
284| [CVE-2013-1636,Candidate,"Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitrary web script or HTML via the get-data parameter.","BUGTRAQ:20130220 [CVE-2013-1636]Wordpress pretty-link plugin XSS in SWF‏] | URL:http://archives.neohapsis.com/archives/bugtraq/2013-02/0101.html | MISC:http://packetstormsecurity.com/files/120433/WordPress-Pretty-Link-1.6.3-Cross-Site-Scripting.html | MISC:http://packetstormsecurity.com/files/121623/Joomla-Jnews-8.0.1-Cross-Site-Scripting.html | MISC:http://wordpress.org/plugins/pretty-link/changelog | CONFIRM:https://civicrm.org/advisory/civi-sa-2013-002-openflashchart-xss | OSVDB:90435 | URL:http://osvdb.org/90435 | XF:prettylinklite-openflashchart-xss(82242) | URL:http://xforce.iss.net/xforce/xfdb/82242",Assigned (20130207),"None (candidate not yet proposed)",
285| [CVE-2013-1656,Candidate,"Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/controllers/spree/admin/payment_methods_controller.rb] and the (2) promotion_action parameter to promotion_actions_controller.rb, (3) promotion_rule parameter to promotion_rules_controller.rb, and (4) calculator_type parameter to promotions_controller.rb in promo/app/controllers/spree/admin/, related to unsafe use of the constantize function.","MISC:http://blog.conviso.com.br/2013/03/spree-commerce-multiple-unsafe.html | MISC:https://www.conviso.com.br/advisories/CVE-2013-1656.txt | CONFIRM:http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed",Assigned (20130211),"None (candidate not yet proposed)",
286| [CVE-2013-1806,Candidate,"Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php] or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to administration/user_fields.php or (3) file parameter to administration/db_backup.php.","FULLDISC:20130228 [waraxe-2013-SA#097] - Multiple Vulnerabilities in PHP-Fusion 7.02.05 | URL:http://seclists.org/fulldisclosure/2013/Feb/154 | MLIST:[oss-security] 20130302 Re: CVE request: PHP-Fusion waraxe-2013-SA#097 | URL:http://www.openwall.com/lists/oss-security/2013/03/03/2 | MLIST:[oss-security] 20130303 CVE request: PHP-Fusion waraxe-2013-SA#097 | URL:http://www.openwall.com/lists/oss-security/2013/03/03/1 | MISC:http://packetstormsecurity.com/files/120598/PHP-Fusion-7.02.05-XSS-LFI-SQL-Injection.html | MISC:http://www.waraxe.us/advisory-97.html | CONFIRM:http://www.php-fusion.co.uk/news.php?readmore=569 | OSVDB:90692 | URL:http://www.osvdb.org/90692 | OSVDB:90694 | URL:http://www.osvdb.org/90694 | OSVDB:90696 | URL:http://www.osvdb.org/90696",Assigned (20130219),"None (candidate not yet proposed)",
287| [CVE-2013-4883,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceId parameter core/loadDisplayType.do] (2) instanceId or (3) monitorUrl parameter to console/createDashboardContainer.do
288| [CVE-2013-5300,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php] the (3) section parameter to av_inventory/task_edit.php
289| [CVE-2013-6078,Candidate,"The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging unspecified ""security concerns,"" aka the ESA-2013-068 issue. NOTE: this issue has been SPLIT from CVE-2007-6755 because the vendor announcement did not state a specific technical rationale for a change in the algorithm] thus, CVE cannot reach a conclusion that a CVE-2007-6755 concern was the reason, or one of the reasons, for this change.","MISC:http://arstechnica.com/security/2013/09/stop-using-nsa-influence-code-in-our-product-rsa-tells-customers/ | MISC:http://blog.cryptographyengineering.com/2013/09/rsa-warns-developers-against-its-own.html | MISC:http://threatpost.com/in-wake-of-latest-crypto-revelations-everything-is-suspect | CONFIRM:http://stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2-332655/",Assigned (20131011),"None (candidate not yet proposed)",
290| [CVE-2013-7105,Candidate,"Buffer overflow in the Interstage HTTP Server log functionality, as used in Fujitsu Interstage Application Server 9.0.0, 9.1.0, 9.2.0, 9.3.1, and 10.0.0] and Interstage Studio 9.0.0, 9.1.0, 9.2.0, and 10.0.0, has unspecified impact and attack vectors related to ""ihsrlog/rotatelogs.""","CONFIRM:http://www.fujitsu.com/global/support/software/security/products-f/interstage-201302e.html | BID:63929 | URL:http://www.securityfocus.com/bid/63929 | SECTRACK:1029398 | URL:http://www.securitytracker.com/id/1029398",Assigned (20131214),"None (candidate not yet proposed)",
291| [CVE-2013-7106,Candidate,"Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the (1) display_nav_table, (2) page_limit_selector, (3) print_export_link, or (4) page_num_selector function in cgi/cgiutils.c] (5) status_page_num_selector function in cgi/status.c
292| [CVE-2013-7190,Candidate,"Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1) tmpid parameter to websitebuilder/showtemplateimage.php, (2) fname parameter to admin/downloadfile.php, or (3) id parameter to support/admin/csvdownload.php] or (4) have an unspecified impact via unspecified vectors in support/parser/main_smtp.php.","FULLDISC:20131215 iscripts autohoster , multiple vulns / php code injection exploit | URL:http://seclists.org/fulldisclosure/2013/Dec/121 | XF:autohoster-mainsmtp-directory-traversal(89818) | URL:http://xforce.iss.net/xforce/xfdb/89818",Assigned (20131220),"None (candidate not yet proposed)",
293| [CVE-2014-0064,Candidate,"Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions] use CVE-2014-2669 for the hstore vector.","CONFIRM:http://wiki.postgresql.org/wiki/20140220securityrelease | CONFIRM:http://www.postgresql.org/about/news/1506/ | CONFIRM:http://www.postgresql.org/support/security/ | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1065230 | CONFIRM:https://github.com/postgres/postgres/commit/31400a673325147e1205326008e32135a78b4d8a | CONFIRM:http://support.apple.com/kb/HT6448 | CONFIRM:https://support.apple.com/kb/HT6536 | APPLE:APPLE-SA-2014-10-16-3 | URL:http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html | DEBIAN:DSA-2864 | URL:http://www.debian.org/security/2014/dsa-2864 | DEBIAN:DSA-2865 | URL:http://www.debian.org/security/2014/dsa-2865 | REDHAT:RHSA-2014:0469 | URL:http://rhn.redhat.com/errata/RHSA-2014-0469.html",Assigned (20131203),"None (candidate not yet proposed)",
294| [CVE-2014-0880,Candidate,"IBM SAN Volume Controller] Storwize V3500, V3700, V5000, and V7000
295| [CVE-2014-2669,Candidate,"Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact via vectors related to the (1) hstore_recv, (2) hstore_from_arrays, and (3) hstore_from_array functions in contrib/hstore/hstore_io.c] and the (4) hstoreArrayToPairs function in contrib/hstore/hstore_op.c, which triggers a buffer overflow. NOTE: this issue was SPLIT from CVE-2014-0064 because it has a different set of affected versions.","CONFIRM:http://wiki.postgresql.org/wiki/20140220securityrelease | CONFIRM:http://www.postgresql.org/about/news/1506/ | CONFIRM:http://www.postgresql.org/support/security/ | CONFIRM:https://github.com/postgres/postgres/commit/31400a673325147e1205326008e32135a78b4d8a | DEBIAN:DSA-2864 | URL:http://www.debian.org/security/2014/dsa-2864 | DEBIAN:DSA-2865 | URL:http://www.debian.org/security/2014/dsa-2865 | REDHAT:RHSA-2014:0469 | URL:http://rhn.redhat.com/errata/RHSA-2014-0469.html",Assigned (20140328),"None (candidate not yet proposed)",
296| [CVE-2014-3040,Candidate,"Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2] Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4
297| [CVE-2014-4608,Candidate,"** DISPUTED ** Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says ""the Linux kernel is *not* affected] media hype.""","MLIST:[oss-security] 20140626 LMS-2014-06-16-2: Linux Kernel LZO | URL:http://www.openwall.com/lists/oss-security/2014/06/26/21 | MISC:http://blog.securitymouse.com/2014/06/raising-lazarus-20-year-old-bug-that.html | MISC:http://www.oberhumer.com/opensource/lzo/ | MISC:https://www.securitymouse.com/lms-2014-06-16-2 | CONFIRM:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git
298| [CVE-2014-4736,Candidate,"SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.","BUGTRAQ:20140723 SQL Injection in Ð] ?2 | URL:http://www.securityfocus.com/archive/1/archive/1/532867/100/0/threaded | MISC:https://www.htbridge.com/advisory/HTB23222 | MISC:http://packetstormsecurity.com/files/127594/E2-2844-SQL-Injection.html | BID:68843 | URL:http://www.securityfocus.com/bid/68843",Assigned (20140708),"None (candidate not yet proposed)",
299| [CVE-2014-5273,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js] (2) ENUM editor page, related to js/functions.js
300| [CVE-2014-6212,Candidate,"The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5] Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5
301| [CVE-2014-6271,Candidate,"GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka ""ShellShock."" NOTE: the original fix for this issue was incorrect] CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.","BUGTRAQ:20141001 NEW VMSA-2014-0010 - VMware product updates address critical Bash security vulnerabilities | URL:http://www.securityfocus.com/archive/1/archive/1/533593/100/0/threaded | EXPLOIT-DB:39918 | URL:https://www.exploit-db.com/exploits/39918/ | FULLDISC:20141001 FW: NEW VMSA-2014-0010 - VMware product updates address critical Bash security vulnerabilities | URL:http://seclists.org/fulldisclosure/2014/Oct/0 | MISC:http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html | MISC:http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html | MISC:http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html | MISC:http://packetstormsecurity.com/files/128573/Apache-mod_cgi-Remote-Command-Execution.html | MISC:http://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.html | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1141597 | CONFIRM:https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/ | CONFIRM:http://support.novell.com/security/cve/CVE-2014-6271.html | CONFIRM:https://www.suse.com/support/shellshock/ | CONFIRM:http://support.apple.com/kb/HT6495 | CONFIRM:http://www.novell.com/support/kb/doc.php?id=7015701 | CONFIRM:https://kb.bluecoat.com/index?page=content&id=SA82 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21685749 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21685914 | CONFIRM:http://www.novell.com/support/kb/doc.php?id=7015721 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html | CONFIRM:http://www.vmware.com/security/advisories/VMSA-2014-0010.html | CONFIRM:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648 | CONFIRM:https://support.apple.com/kb/HT6535 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21686084 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21685541 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21685604 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21685733 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21686131 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21686479 | CONFIRM:http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315 | CONFIRM:https://support.citrix.com/article/CTX200217 | CONFIRM:https://support.citrix.com/article/CTX200223 | CONFIRM:https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21686246 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21686445 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21686494 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21687079 | CONFIRM:https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts | CONFIRM:http://www.qnap.com/i/en/support/con_show.php?cid=61 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21686447 | CONFIRM:http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0 | CONFIRM:http://advisories.mageia.org/MGASA-2014-0388.html | CONFIRM:https://access.redhat.com/articles/1200223 | APPLE:APPLE-SA-2014-10-16-1 | URL:http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html | CISCO:20140926 GNU Bash Environmental Variable Command Injection Vulnerability | URL:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash | DEBIAN:DSA-3032 | URL:http://www.debian.org/security/2014/dsa-3032 | HP:HPSBGN03117 | URL:http://marc.info/?l=bugtraq&m=141216207813411&w=2 | HP:HPSBHF03119 | URL:http://marc.info/?l=bugtraq&m=141216668515282&w=2 | HP:HPSBHF03124 | URL:http://marc.info/?l=bugtraq&m=141235957116749&w=2 | HP:HPSBST03122 | URL:http://marc.info/?l=bugtraq&m=141319209015420&w=2 | HP:HPSBGN03138 | URL:http://marc.info/?l=bugtraq&m=141330468527613&w=2 | HP:HPSBHF03125 | URL:http://marc.info/?l=bugtraq&m=141345648114150&w=2 | HP:HPSBMU03133 | URL:http://marc.info/?l=bugtraq&m=141330425327438&w=2 | HP:HPSBGN03141 | URL:http://marc.info/?l=bugtraq&m=141383304022067&w=2 | HP:HPSBGN03142 | URL:http://marc.info/?l=bugtraq&m=141383244821813&w=2 | HP:HPSBHF03146 | URL:http://marc.info/?l=bugtraq&m=141383353622268&w=2 | HP:HPSBMU03143 | URL:http://marc.info/?l=bugtraq&m=141383026420882&w=2 | HP:HPSBMU03144 | URL:http://marc.info/?l=bugtraq&m=141383081521087&w=2 | HP:HPSBST03129 | URL:http://marc.info/?l=bugtraq&m=141383196021590&w=2 | HP:HPSBST03131 | URL:http://marc.info/?l=bugtraq&m=141383138121313&w=2 | HP:HPSBST03157 | URL:http://marc.info/?l=bugtraq&m=141450491804793&w=2 | HP:HPSBHF03145 | URL:http://marc.info/?l=bugtraq&m=141383465822787&w=2 | HP:HPSBMU03165 | URL:http://marc.info/?l=bugtraq&m=141577137423233&w=2 | HP:HPSBMU03182 | URL:http://marc.info/?l=bugtraq&m=141585637922673&w=2 | HP:HPSBST03154 | URL:http://marc.info/?l=bugtraq&m=141577297623641&w=2 | HP:HPSBST03155 | URL:http://marc.info/?l=bugtraq&m=141576728022234&w=2 | HP:HPSBST03181 | URL:http://marc.info/?l=bugtraq&m=141577241923505&w=2 | HP:HPSBST03148 | URL:http://marc.info/?l=bugtraq&m=141694386919794&w=2 | HP:HPSBST03265 | URL:http://marc.info/?l=bugtraq&m=142546741516006&w=2 | HP:HPSBMU03217 | URL:http://marc.info/?l=bugtraq&m=141879528318582&w=2 | HP:HPSBMU03245 | URL:http://marc.info/?l=bugtraq&m=142358026505815&w=2 | HP:HPSBMU03246 | URL:http://marc.info/?l=bugtraq&m=142358078406056&w=2 | HP:HPSBOV03228 | URL:http://marc.info/?l=bugtraq&m=142113462216480&w=2 | HP:SSRT101711 | URL:http://marc.info/?l=bugtraq&m=142113462216480&w=2 | HP:SSRT101742 | URL:http://marc.info/?l=bugtraq&m=142358026505815&w=2 | HP:SSRT101827 | URL:http://marc.info/?l=bugtraq&m=141879528318582&w=2 | HP:HPSBGN03233 | URL:http://marc.info/?l=bugtraq&m=142118135300698&w=2 | HP:SSRT101739 | URL:http://marc.info/?l=bugtraq&m=142118135300698&w=2 | HP:SSRT101868 | URL:http://marc.info/?l=bugtraq&m=142118135300698&w=2 | HP:HPSBMU03220 | URL:http://marc.info/?l=bugtraq&m=142721162228379&w=2 | HP:HPSBST03196 | URL:http://marc.info/?l=bugtraq&m=142719845423222&w=2 | HP:SSRT101816 | URL:http://marc.info/?l=bugtraq&m=142719845423222&w=2 | HP:SSRT101819 | URL:http://marc.info/?l=bugtraq&m=142721162228379&w=2 | HP:HPSBST03195 | URL:http://marc.info/?l=bugtraq&m=142805027510172&w=2 | MANDRIVA:MDVSA-2015:164 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2015:164 | REDHAT:RHSA-2014:1293 | URL:http://rhn.redhat.com/errata/RHSA-2014-1293.html | REDHAT:RHSA-2014:1294 | URL:http://rhn.redhat.com/errata/RHSA-2014-1294.html | REDHAT:RHSA-2014:1295 | URL:http://rhn.redhat.com/errata/RHSA-2014-1295.html | REDHAT:RHSA-2014:1354 | URL:http://rhn.redhat.com/errata/RHSA-2014-1354.html | SUSE:SUSE-SU-2014:1223 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00034.html | SUSE:SUSE-SU-2014:1260 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00049.html | SUSE:openSUSE-SU-2014:1238 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00040.html | SUSE:openSUSE-SU-2014:1254 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html | SUSE:SUSE-SU-2014:1287 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html | SUSE:openSUSE-SU-2014:1308 | URL:http://lists.opensuse.org/opensuse-updates/2014-10/msg00023.html | SUSE:openSUSE-SU-2014:1310 | URL:http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html | SUSE:openSUSE-SU-2014:1226 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00037.html | SUSE:SUSE-SU-2014:1212 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00028.html | SUSE:SUSE-SU-2014:1213 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00029.html | UBUNTU:USN-2362-1 | URL:http://www.ubuntu.com/usn/USN-2362-1 | CERT:TA14-268A | URL:http://www.us-cert.gov/ncas/alerts/TA14-268A | CERT-VN:VU#252743 | URL:http://www.kb.cert.org/vuls/id/252743 | JVN:JVN#55667175 | URL:http://jvn.jp/en/jp/JVN55667175/index.html | JVNDB:JVNDB-2014-000126 | URL:http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 | SECUNIA:59737 | URL:http://secunia.com/advisories/59737 | SECUNIA:61641 | URL:http://secunia.com/advisories/61641 | SECUNIA:61676 | URL:http://secunia.com/advisories/61676 | SECUNIA:61700 | URL:http://secunia.com/advisories/61700 | SECUNIA:59907 | URL:http://secunia.com/advisories/59907 | SECUNIA:61283 | URL:http://secunia.com/advisories/61283 | SECUNIA:61485 | URL:http://secunia.com/advisories/61485 | SECUNIA:61503 | URL:http://secunia.com/advisories/61503 | SECUNIA:61552 | URL:http://secunia.com/advisories/61552 | SECUNIA:61565 | URL:http://secunia.com/advisories/61565 | SECUNIA:61603 | URL:http://secunia.com/advisories/61603 | SECUNIA:61633 | URL:http://secunia.com/advisories/61633 | SECUNIA:61643 | URL:http://secunia.com/advisories/61643 | SECUNIA:61654 | URL:http://secunia.com/advisories/61654 | SECUNIA:61703 | URL:http://secunia.com/advisories/61703 | SECUNIA:61711 | URL:http://secunia.com/advisories/61711 | SECUNIA:61715 | URL:http://secunia.com/advisories/61715 | SECUNIA:60947 | URL:http://secunia.com/advisories/60947 | SECUNIA:61188 | URL:http://secunia.com/advisories/61188 | SECUNIA:58200 | URL:http://secunia.com/advisories/58200 | SECUNIA:60034 | URL:http://secunia.com/advisories/60034 | SECUNIA:60055 | URL:http://secunia.com/advisories/60055 | SECUNIA:60193 | URL:http://secunia.com/advisories/60193 | SECUNIA:60325 | URL:http://secunia.com/advisories/60325 | SECUNIA:61065 | URL:http://secunia.com/advisories/61065 | SECUNIA:61128 | URL:http://secunia.com/advisories/61128 | SECUNIA:61129 | URL:http://secunia.com/advisories/61129 | SECUNIA:61287 | URL:http://secunia.com/advisories/61287 | SECUNIA:61312 | URL:http://secunia.com/advisories/61312 | SECUNIA:61313 | URL:http://secunia.com/advisories/61313 | SECUNIA:61328 | URL:http://secunia.com/advisories/61328 | SECUNIA:61442 | URL:http://secunia.com/advisories/61442 | SECUNIA:61471 | URL:http://secunia.com/advisories/61471 | SECUNIA:61550 | URL:http://secunia.com/advisories/61550 | SECUNIA:61780 | URL:http://secunia.com/advisories/61780 | SECUNIA:61816 | URL:http://secunia.com/advisories/61816 | SECUNIA:61855 | URL:http://secunia.com/advisories/61855 | SECUNIA:61857 | URL:http://secunia.com/advisories/61857 | SECUNIA:60024 | URL:http://secunia.com/advisories/60024 | SECUNIA:60063 | URL:http://secunia.com/advisories/60063 | SECUNIA:60044 | URL:http://secunia.com/advisories/60044 | SECUNIA:60433 | URL:http://secunia.com/advisories/60433 | SECUNIA:61291 | URL:http://secunia.com/advisories/61291 | SECUNIA:61873 | URL:http://secunia.com/advisories/61873 | SECUNIA:62312 | URL:http://secunia.com/advisories/62312 | SECUNIA:62343 | URL:http://secunia.com/advisories/62343",Assigned (20140909),"None (candidate not yet proposed)",
302| [CVE-2014-7252,Candidate,"Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D] and SoftBank SHARP handsets 102SH allow local users to execute arbitrary code or read kernel memory via unknown vectors related to userland data and ""improper data validation.""","MISC:http://jvn.jp/en/jp/JVN67792023/397327/index.html | MISC:http://jvn.jp/en/jp/JVN67792023/995312/index.html | JVN:JVN#67792023 | URL:http://jvn.jp/en/jp/JVN67792023/index.html | JVNDB:JVNDB-2014-000137 | URL:http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000137.html",Assigned (20140930),"None (candidate not yet proposed)",
303| [CVE-2014-9580,Candidate,"Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the Description field in a file upload. NOTE: this issue was originally incorrectly mapped to CVE-2014-1155] see CVE-2014-1155 for more information.","EXPLOIT-DB:35582 | URL:http://www.exploit-db.com/exploits/35582 | MISC:http://packetstormsecurity.com/files/129666 | XF:projectsend-imagedescrip-xss(99550) | URL:http://xforce.iss.net/xforce/xfdb/99550",Assigned (20150108),"None (candidate not yet proposed)",
304| [CVE-2014-9736,Candidate,"GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key manager and (2) server keystore] (3) keystore_password for the server truststore
305| [CVE-2015-0551,Candidate,"Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01] Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01
306| [CVE-2015-1314,Candidate,"The USAA Mobile Banking application before 7.10.1 for Android displays the most recently-used screen before prompting the user for login, which might allow physically proximate users to obtain banking account numbers and balances.","FULLDISC:20150122 USAA mobile app gives away personal data] fix released | URL:http://seclists.org/fulldisclosure/2015/Jan/94 | MISC:http://dnlongen.blogspot.com/2015/01/usaa-mobile-app-gives-away-your-account.html | MISC:http://packetstormsecurity.com/files/130067/USAA-Mobile-App-Information-Disclosure.html",Assigned (20150122),"None (candidate not yet proposed)",
307| [CVE-2015-1574,Candidate,"The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a ""Content-Disposition: ] "" header in an e-mail message.","BUGTRAQ:20150213 CVE-2015-1574 - Google Email App 4.2.2 remote denial of service | URL:http://www.securityfocus.com/archive/1/archive/1/534703/100/0/threaded | FULLDISC:20150214 CVE-2015-1574 - Google Email App 4.2.2 remote denial of service | URL:http://seclists.org/fulldisclosure/2015/Feb/58 | MLIST:[oss-security] 20150210 Re: Re: CVE-Request -- Google Email App 4.2.2 remote denial of service | URL:http://openwall.com/lists/oss-security/2015/02/10/9 | MLIST:[oss-security] 20150212 Re: CVE-Request -- Google Email App 4.2.2 remote denial of service | URL:http://openwall.com/lists/oss-security/2015/02/12/15 | MISC:http://hmarco.org/bugs/google_email_app_4.2.2_denial_of_service.html | MISC:http://packetstormsecurity.com/files/130388/Google-Email-4.4.2.0200-Denial-Of-Service.html",Assigned (20150211),"None (candidate not yet proposed)",
308| [CVE-2015-1576,Candidate,"Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.php, (5) new2.php, or (6) rename2.php in u5admin/] (7) c parameter to u5admin/editor.php
309| [CVE-2015-4091,Candidate,"XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly have unspecified other impact via an XML request to tc~sld~wd~main/Main, related to ""CIM UPLOAD,"" aka SAP Security Note 2090851.","BUGTRAQ:20150817 [ERPSCAN-15-013] SAP NetWeaver AS Java CIM UPLOAD â] ?? XXE | URL:http://www.securityfocus.com/archive/1/archive/1/536239/100/0/threaded | FULLDISC:20150522 SAP Security Notes May 2015 | URL:http://seclists.org/fulldisclosure/2015/May/96 | MISC:http://erpscan.com/advisories/erpscan-15-013-sap-netweaver-as-java-cim-upload-xxe | MISC:http://packetstormsecurity.com/files/133122/SAP-NetWeaver-AS-Java-XXE-Injection.html",Assigned (20150526),"None (candidate not yet proposed)",
310| [CVE-2015-4524,Candidate,"Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01] Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01
311| [CVE-2015-4744,Candidate,"Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2] and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect integrity via unknown vectors related to Java Server Faces.","CONFIRM:http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html",Assigned (20150624),"None (candidate not yet proposed)",
312| [CVE-2015-4950,Candidate,"The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2] Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.1
313| [CVE-2015-6557,Candidate,"IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2] Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2
314| [CVE-2015-7387,Candidate,"ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do, as demonstrated by ""SELECT 1] INSERT INTO.""","EXPLOIT-DB:38173 | URL:https://www.exploit-db.com/exploits/38173/ | EXPLOIT-DB:38352 | URL:https://www.exploit-db.com/exploits/38352/ | FULLDISC:20150915 ManageEngine EventLog Analyzer SQL query execution | URL:http://seclists.org/fulldisclosure/2015/Sep/59 | MISC:http://packetstormsecurity.com/files/133581/ManageEngine-EventLog-Analyzer-10.6-Build-10060-SQL-Query-Execution.html | MISC:http://packetstormsecurity.com/files/133747/ManageEngine-EventLog-Analyzer-Remote-Code-Execution.html",Assigned (20150928),"None (candidate not yet proposed)",
315| [CVE-2015-7404,Candidate,"IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka Spectrum Protect for Databases) 5.5 before 5.5.6.2, 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4] Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server (aka Spectrum Protect for Mail) 5.5 before 5.5.1.1, 6.1 and 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4
316| [CVE-2016-1926,Candidate,"Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a get_aggregate command to omp.","BUGTRAQ:20160120 [CVE-2016-1926] XSS in Greenbone Security Assistant &ge] 6.0.0 and < 6.0.8 | URL:http://www.securityfocus.com/archive/1/archive/1/537335/100/0/threaded | MISC:http://packetstormsecurity.com/files/135328/OpenVAS-Greenbone-Security-Assistant-Cross-Site-Scripting.html | MISC:https://en.internetwache.org/cve-2016-1926-xss-in-the-greenbone-security-assistant-20-01-2016/ | CONFIRM:http://www.greenbone.net/technology/gbsa2016-01.html | CONFIRM:http://www.openvas.org/OVSA20160113.html | FEDORA:FEDORA-2016-9851b69dbb | URL:http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184478.html | FEDORA:FEDORA-2016-afdedc8da9 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183371.html",Assigned (20160118),"None (candidate not yet proposed)",
317| [CVE-2016-2076,Candidate,"Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2] vCloud Director 5.5.5
318| [CVE-2016-3458,Candidate,"Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92] and Java SE Embedded 8u91 allows remote attackers to affect integrity via vectors related to CORBA.","CONFIRM:http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",Assigned (20160317),"None (candidate not yet proposed)",