· 9 years ago · Dec 09, 2016, 12:22 AM
1| MITRE CVE - http://cve.mitre.org:
2
3| [CVE-2004-0656] The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.
4
5|
6
7| OSVDB - http://www.osvdb.org:
8
9| No findings
10
11|
12
13| SecurityFocus - http://www.securityfocus.com/bid/:
14
15| [10664] PureFTPd Accept_Client Remote Denial of Service Vulnerability
16
17|
18
19| SecurityTracker - http://www.securitytracker.com:
20
21| [1010701] PureFTPd Logic Bug in accept_client() Lets Remote Users Crash the FTP Daemon
22
23| [1008135] (Claim is Retracted) PureFTPd Buffer Overflow in displayrate() Lets Remote Users Crash the Service
24
25| [1002993] PurePostPro Script Add-on for PureFTPd and MySQL Allows Remote Users to Execute SQL Commands on the Server
26
27| [1001126] PureFTPd May Allow Remote Users to Deny Service on the Server
28
29|
30
31| IBM X-Force - http://xforce.iss.net:
32
33| No findings
34
35|
36
37| Exploit-DB - http://www.exploit-db.com:
38
39| No findings
40
41|
42
43| OpenVAS (Nessus) - http://www.openvas.org:
44
45| No findings
46
47|_
48
4922/tcp open ssh OpenSSH 5.3 (protocol 2.0)
50
51| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
52
53| [4584] OpenSSH up to 5.7 auth-options.c information disclosure
54
55| [4282] OpenSSH 5.x Legacy Certificate Handler buffer overflow
56
57|
58
59| MITRE CVE - http://cve.mitre.org:
60
61| [CVE-2006-0883] OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.
62
63| [CVE-2012-0814] The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite. NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized_keys file in its own home directory.
64
65| [CVE-2011-5000] The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.
66
67| [CVE-2011-0539] The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.
68
69| [CVE-2010-4755] The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in SSH_FXP_STAT requests to an sftp daemon, a different vulnerability than CVE-2010-2632.
70
71| [CVE-2010-4478] OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.
72
73| [CVE-2009-2904] A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory, related to requirements for directory ownership.
74
75| [CVE-2008-3844] Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.
76
77| [CVE-2008-3259] OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX platform.
78
79|
80
81| OSVDB - http://www.osvdb.org:
82
83| [92034] GSI-OpenSSH auth-pam.c Memory Management Authentication Bypass
84
85| [90474] Red Hat / Fedora PAM Module for OpenSSH Incorrect error() Function Calling Local Privilege Escalation
86
87| [90007] OpenSSH logingracetime / maxstartup Threshold Connection Saturation Remote DoS
88
89| [81500] OpenSSH gss-serv.c ssh_gssapi_parse_ename Function Field Length Value Parsing Remote DoS
90
91| [78706] OpenSSH auth-options.c sshd auth_parse_options Function authorized_keys Command Option Debug Message Information Disclosure
92
93| [75753] OpenSSH PAM Module Aborted Conversation Local Information Disclosure
94
95| [75249] OpenSSH sftp-glob.c remote_glob Function Glob Expression Parsing Remote DoS
96
97| [75248] OpenSSH sftp.c process_put Function Glob Expression Parsing Remote DoS
98
99| [72183] Portable OpenSSH ssh-keysign ssh-rand-helper Utility File Descriptor Leak Local Information Disclosure
100
101| [70873] OpenSSH Legacy Certificates Stack Memory Disclosure
102
103| [69658] OpenSSH J-PAKE Public Parameter Validation Shared Secret Authentication Bypass
104
105| [67743] Novell NetWare OpenSSH SSHD.NLM Absolute Path Handling Remote Overflow
106
107| [59353] OpenSSH sshd Local TCP Redirection Connection Masking Weakness
108
109| [58495] OpenSSH sshd ChrootDirectory Feature SetUID Hard Link Local Privilege Escalation
110
111| [56921] OpenSSH Unspecified Remote Compromise
112
113| [53021] OpenSSH on ftp.openbsd.org Trojaned Distribution
114
115| [50036] OpenSSH CBC Mode Chosen Ciphertext 32-bit Chunk Plaintext Context Disclosure
116
117| [49386] OpenSSH sshd TCP Connection State Remote Account Enumeration
118
119| [48791] OpenSSH on Debian sshd Crafted Username Arbitrary Remote SELinux Role Access
120
121| [47635] OpenSSH Packages on Red Hat Enterprise Linux Compromised Distribution
122
123| [47227] OpenSSH X11UseLocalhost X11 Forwarding Port Hijacking
124
125| [45873] Cisco WebNS SSHield w/ OpenSSH Crafted Large Packet Remote DoS
126
127| [43911] OpenSSH ~/.ssh/rc ForceCommand Bypass Arbitrary Command Execution
128
129| [43745] OpenSSH X11 Forwarding Local Session Hijacking
130
131| [43371] OpenSSH Trusted X11 Cookie Connection Policy Bypass
132
133| [39214] OpenSSH linux_audit_record_event Crafted Username Audit Log Injection
134
135| [37315] pam_usb OpenSSH Authentication Unspecified Issue
136
137| [34850] OpenSSH on Mac OS X Key Generation Remote Connection DoS
138
139| [34601] OPIE w/ OpenSSH Account Enumeration
140
141| [34600] OpenSSH S/KEY Authentication Account Enumeration
142
143| [32721] OpenSSH Username Password Complexity Account Enumeration
144
145| [30232] OpenSSH Privilege Separation Monitor Weakness
146
147| [29494] OpenSSH packet.c Invalid Protocol Sequence Remote DoS
148
149| [29266] OpenSSH GSSAPI Authentication Abort Username Enumeration
150
151| [29264] OpenSSH Signal Handler Pre-authentication Race Condition Code Execution
152
153| [29152] OpenSSH Identical Block Packet DoS
154
155| [27745] Apple Mac OS X OpenSSH Nonexistent Account Login Enumeration DoS
156
157| [23797] OpenSSH with OpenPAM Connection Saturation Forked Process Saturation DoS
158
159| [22692] OpenSSH scp Command Line Filename Processing Command Injection
160
161| [20216] OpenSSH with KerberosV Remote Authentication Bypass
162
163| [19142] OpenSSH Multiple X11 Channel Forwarding Leaks
164
165| [19141] OpenSSH GSSAPIAuthentication Credential Escalation
166
167| [18236] OpenSSH no pty Command Execution Local PAM Restriction Bypass
168
169| [16567] OpenSSH Privilege Separation LoginGraceTime DoS
170
171| [16039] Solaris 108994 Series Patch OpenSSH LDAP Client Authentication DoS
172
173| [9562] OpenSSH Default Configuration Anon SSH Service Port Bounce Weakness
174
175| [9550] OpenSSH scp Traversal Arbitrary File Overwrite
176
177| [6601] OpenSSH *realloc() Unspecified Memory Errors
178
179| [6245] OpenSSH SKEY/BSD_AUTH Challenge-Response Remote Overflow
180
181| [6073] OpenSSH on FreeBSD libutil Arbitrary File Read
182
183| [6072] OpenSSH PAM Conversation Function Stack Modification
184
185| [6071] OpenSSH SSHv1 PAM Challenge-Response Authentication Privilege Escalation
186
187| [5536] OpenSSH sftp-server Restricted Keypair Restriction Bypass
188
189| [5408] OpenSSH echo simulation Information Disclosure
190
191| [5113] OpenSSH NIS YP Netgroups Authentication Bypass
192
193| [4536] OpenSSH Portable AIX linker Privilege Escalation
194
195| [3938] OpenSSL and OpenSSH /dev/random Check Failure
196
197| [3456] OpenSSH buffer_append_space() Heap Corruption
198
199| [2557] OpenSSH Multiple Buffer Management Multiple Overflows
200
201| [2140] OpenSSH w/ PAM Username Validity Timing Attack
202
203| [2112] OpenSSH Reverse DNS Lookup Bypass
204
205| [2109] OpenSSH sshd Root Login Timing Side-Channel Weakness
206
207| [1853] OpenSSH Symbolic Link 'cookies' File Removal
208
209| [839] OpenSSH PAMAuthenticationViaKbdInt Challenge-Response Remote Overflow
210
211| [781] OpenSSH Kerberos TGT/AFS Token Passing Remote Overflow
212
213| [730] OpenSSH Channel Code Off by One Remote Privilege Escalation
214
215| [688] OpenSSH UseLogin Environment Variable Local Command Execution
216
217| [642] OpenSSH Multiple Key Type ACL Bypass
218
219| [504] OpenSSH SSHv2 Public Key Authentication Bypass
220
221| [341] OpenSSH UseLogin Local Privilege Escalation
222
223|
224
225| SecurityFocus - http://www.securityfocus.com/bid/:
226
227| [61286] OpenSSH Remote Denial of Service Vulnerability
228
229| [58894] GSI-OpenSSH PAM_USER Security Bypass Vulnerability
230
231| [58162] OpenSSH CVE-2010-5107 Denial of Service Vulnerability
232
233| [54114] OpenSSH 'ssh_gssapi_parse_ename()' Function Denial of Service Vulnerability
234
235| [51702] Debian openssh-server Forced Command Handling Information Disclosure Vulnerability
236
237| [50416] Linux Kernel 'kdump' and 'mkdumprd' OpenSSH Integration Remote Information Disclosure Vulnerability
238
239| [49473] OpenSSH Ciphersuite Specification Information Disclosure Weakness
240
241| [48507] OpenSSH 'pam_thread()' Remote Buffer Overflow Vulnerability
242
243| [47691] Portable OpenSSH 'ssh-keysign' Local Unauthorized Access Vulnerability
244
245| [46155] OpenSSH Legacy Certificate Signing Information Disclosure Vulnerability
246
247| [45304] OpenSSH J-PAKE Security Bypass Vulnerability
248
249| [36552] Red Hat Enterprise Linux OpenSSH 'ChrootDirectory' Option Local Privilege Escalation Vulnerability
250
251| [32319] OpenSSH CBC Mode Information Disclosure Vulnerability
252
253| [30794] Red Hat OpenSSH Backdoor Vulnerability
254
255| [30339] OpenSSH 'X11UseLocalhost' X11 Forwarding Session Hijacking Vulnerability
256
257| [30276] Debian OpenSSH SELinux Privilege Escalation Vulnerability
258
259| [28531] OpenSSH ForceCommand Command Execution Weakness
260
261| [28444] OpenSSH X Connections Session Hijacking Vulnerability
262
263| [26097] OpenSSH LINUX_AUDIT_RECORD_EVENT Remote Log Injection Weakness
264
265| [25628] OpenSSH X11 Cookie Local Authentication Bypass Vulnerability
266
267| [23601] OpenSSH S/Key Remote Information Disclosure Vulnerability
268
269| [20956] OpenSSH Privilege Separation Key Signature Weakness
270
271| [20418] OpenSSH-Portable Existing Password Remote Information Disclosure Weakness
272
273| [20245] OpenSSH-Portable GSSAPI Authentication Abort Information Disclosure Weakness
274
275| [20241] Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
276
277| [20216] OpenSSH Duplicated Block Remote Denial of Service Vulnerability
278
279| [16892] OpenSSH Remote PAM Denial Of Service Vulnerability
280
281| [14963] OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
282
283| [14729] OpenSSH GSSAPI Credential Disclosure Vulnerability
284
285| [14727] OpenSSH DynamicForward Inadvertent GatewayPorts Activation Vulnerability
286
287| [11781] OpenSSH-portable PAM Authentication Remote Information Disclosure Vulnerability
288
289| [9986] RCP, OpenSSH SCP Client File Corruption Vulnerability
290
291| [9040] OpenSSH PAM Conversation Memory Scrubbing Weakness
292
293| [8677] Multiple Portable OpenSSH PAM Vulnerabilities
294
295| [8628] OpenSSH Buffer Mismanagement Vulnerabilities
296
297| [7831] OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
298
299| [7482] OpenSSH Remote Root Authentication Timing Side-Channel Weakness
300
301| [7467] OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
302
303| [7343] OpenSSH Authentication Execution Path Timing Information Leakage Weakness
304
305| [6168] OpenSSH Visible Password Vulnerability
306
307| [5374] OpenSSH Trojan Horse Vulnerability
308
309| [5093] OpenSSH Challenge-Response Buffer Overflow Vulnerabilities
310
311| [4560] OpenSSH Kerberos 4 TGT/AFS Token Buffer Overflow Vulnerability
312
313| [4241] OpenSSH Channel Code Off-By-One Vulnerability
314
315| [3614] OpenSSH UseLogin Environment Variable Passing Vulnerability
316
317| [3560] OpenSSH Kerberos Arbitrary Privilege Elevation Vulnerability
318
319| [3369] OpenSSH Key Based Source IP Access Control Bypass Vulnerability
320
321| [3345] OpenSSH SFTP Command Restriction Bypassing Vulnerability
322
323| [2917] OpenSSH PAM Session Evasion Vulnerability
324
325| [2825] OpenSSH Client X11 Forwarding Cookie Removal File Symbolic Link Vulnerability
326
327| [2356] OpenSSH Private Key Authentication Check Vulnerability
328
329| [1949] OpenSSH Client Unauthorized Remote Forwarding Vulnerability
330
331| [1334] OpenSSH UseLogin Vulnerability
332
333|
334
335| SecurityTracker - http://www.securitytracker.com:
336
337| [1028187] OpenSSH pam_ssh_agent_auth Module on Red Hat Enterprise Linux Lets Remote Users Execute Arbitrary Code
338
339| [1026593] OpenSSH Lets Remote Authenticated Users Obtain Potentially Sensitive Information
340
341| [1025739] OpenSSH on FreeBSD Has Buffer Overflow in pam_thread() That Lets Remote Users Execute Arbitrary Code
342
343| [1025482] OpenSSH ssh-keysign Utility Lets Local Users Gain Elevated Privileges
344
345| [1025028] OpenSSH Legacy Certificates May Disclose Stack Contents to Remote Users
346
347| [1022967] OpenSSH on Red Hat Enterprise Linux Lets Remote Authenticated Users Gain Elevated Privileges
348
349| [1021235] OpenSSH CBC Mode Error Handling May Let Certain Remote Users Obtain Plain Text in Certain Cases
350
351| [1020891] OpenSSH on Debian Lets Remote Users Prevent Logins
352
353| [1020730] OpenSSH for Red Hat Enterprise Linux Packages May Have Been Compromised
354
355| [1020537] OpenSSH on HP-UX Lets Local Users Hijack X11 Sessions
356
357| [1019733] OpenSSH Unsafe Default Configuration May Let Local Users Execute Arbitrary Commands
358
359| [1019707] OpenSSH Lets Local Users Hijack Forwarded X Sessions in Certain Cases
360
361| [1017756] Apple OpenSSH Key Generation Process Lets Remote Users Deny Service
362
363| [1017183] OpenSSH Privilege Separation Monitor Validation Error May Cause the Monitor to Fail to Properly Control the Unprivileged Process
364
365| [1016940] OpenSSH Race Condition in Signal Handler Lets Remote Users Deny Service and May Potentially Permit Code Execution
366
367| [1016939] OpenSSH GSSAPI Authentication Abort Error Lets Remote Users Determine Valid Usernames
368
369| [1016931] OpenSSH SSH v1 CRC Attack Detection Implementation Lets Remote Users Deny Service
370
371| [1016672] OpenSSH on Mac OS X Lets Remote Users Deny Service
372
373| [1015706] OpenSSH Interaction With OpenPAM Lets Remote Users Deny Service
374
375| [1015540] OpenSSH scp Double Shell Character Expansion During Local-to-Local Copying May Let Local Users Gain Elevated Privileges in Certain Cases
376
377| [1014845] OpenSSH May Unexpectedly Activate GatewayPorts and Also May Disclose GSSAPI Credentials in Certain Cases
378
379| [1011193] OpenSSH scp Directory Traversal Flaw Lets Remote SSH Servers Overwrite Files in Certain Cases
380
381| [1011143] OpenSSH Default Configuration May Be Unsafe When Used With Anonymous SSH Services
382
383| [1007791] Portable OpenSSH PAM free() Bug May Let Remote Users Execute Root Code
384
385| [1007716] OpenSSH buffer_append_space() and Other Buffer Management Errors May Let Remote Users Execute Arbitrary Code
386
387| [1006926] OpenSSH Host Access Restrictions Can Be Bypassed By Remote Users
388
389| [1006688] OpenSSH Timing Flaw With Pluggable Authentication Modules Can Disclose Valid User Account Names to Remote Users
390
391| [1004818] OpenSSH's Secure Shell (SSH) Implementation Weakness May Disclose User Passwords to Remote Users During Man-in-the-Middle Attacks
392
393| [1004616] OpenSSH Integer Overflow and Buffer Overflow May Allow Remote Users to Gain Root Access to the System
394
395| [1004391] OpenSSH 'BSD_AUTH' Access Control Bug May Allow Unauthorized Remote Users to Authenticated to the System
396
397| [1004115] OpenSSH Buffer Overflow in Kerberos Ticket and AFS Token Processing Lets Local Users Execute Arbitrary Code With Root Level Permissions
398
399| [1003758] OpenSSH Off-by-one 'Channels' Bug May Let Authorized Remote Users Execute Arbitrary Code with Root Privileges
400
401| [1002895] OpenSSH UseLogin Environment Variable Bug Lets Local Users Execute Commands and Gain Root Access
402
403| [1002748] OpenSSH 3.0 Denial of Service Condition May Allow Remote Users to Crash the sshd Daemon and KerberosV Configuration Error May Allow Remote Users to Partially Authenticate When Authentication Should Not Be Permitted
404
405| [1002734] OpenSSH's S/Key Implementation Information Disclosure Flaw Provides Remote Users With Information About Valid User Accounts
406
407| [1002455] OpenSSH May Fail to Properly Restrict IP Addresses in Certain Configurations
408
409| [1002432] OpenSSH's Sftp-server Subsystem Lets Authorized Remote Users with Restricted Keypairs Obtain Additional Access on the Server
410
411| [1001683] OpenSSH Allows Authorized Users to Delete Other User Files Named Cookies
412
413|
414
415| IBM X-Force - http://xforce.iss.net:
416
417| [83258] GSI-OpenSSH auth-pam.c security bypass
418
419| [82781] OpenSSH time limit denial of service
420
421| [82231] OpenSSH pam_ssh_agent_auth PAM code execution
422
423| [74809] OpenSSH ssh_gssapi_parse_ename denial of service
424
425| [72756] Debian openssh-server commands information disclosure
426
427| [68339] OpenSSH pam_thread buffer overflow
428
429| [67264] OpenSSH ssh-keysign unauthorized access
430
431| [65910] OpenSSH remote_glob function denial of service
432
433| [65163] OpenSSH certificate information disclosure
434
435| [64387] OpenSSH J-PAKE security bypass
436
437| [63337] Cisco Unified Videoconferencing OpenSSH weak security
438
439| [46620] OpenSSH and multiple SSH Tectia products CBC mode information disclosure
440
441| [45202] OpenSSH signal handler denial of service
442
443| [44747] RHEL OpenSSH backdoor
444
445| [44280] OpenSSH PermitRootLogin information disclosure
446
447| [44279] OpenSSH sshd weak security
448
449| [44037] OpenSSH sshd SELinux role unauthorized access
450
451| [43940] OpenSSH X11 forwarding information disclosure
452
453| [41549] OpenSSH ForceCommand directive security bypass
454
455| [41438] OpenSSH sshd session hijacking
456
457| [40897] OpenSSH known_hosts weak security
458
459| [40587] OpenSSH username weak security
460
461| [37371] OpenSSH username data manipulation
462
463| [37118] RHSA update for OpenSSH privilege separation monitor authentication verification weakness not installed
464
465| [37112] RHSA update for OpenSSH signal handler race condition not installed
466
467| [37107] RHSA update for OpenSSH identical block denial of service not installed
468
469| [36637] OpenSSH X11 cookie privilege escalation
470
471| [35167] OpenSSH packet.c newkeys[mode] denial of service
472
473| [34490] OpenSSH OPIE information disclosure
474
475| [33794] OpenSSH ChallengeResponseAuthentication information disclosure
476
477| [32975] Apple Mac OS X OpenSSH denial of service
478
479| [32387] RHSA-2006:0738 updates for openssh not installed
480
481| [32359] RHSA-2006:0697 updates for openssh not installed
482
483| [32230] RHSA-2006:0298 updates for openssh not installed
484
485| [32132] RHSA-2006:0044 updates for openssh not installed
486
487| [30120] OpenSSH privilege separation monitor authentication verification weakness
488
489| [29255] OpenSSH GSSAPI user enumeration
490
491| [29254] OpenSSH signal handler race condition
492
493| [29158] OpenSSH identical block denial of service
494
495| [28147] Apple Mac OS X OpenSSH nonexistent user login denial of service
496
497| [25116] OpenSSH OpenPAM denial of service
498
499| [24305] OpenSSH SCP shell expansion command execution
500
501| [22665] RHSA-2005:106 updates for openssh not installed
502
503| [22117] OpenSSH GSSAPI allows elevated privileges
504
505| [22115] OpenSSH GatewayPorts security bypass
506
507| [20930] OpenSSH sshd.c LoginGraceTime denial of service
508
509| [19441] Sun Solaris OpenSSH LDAP (1) client authentication denial of service
510
511| [17213] OpenSSH allows port bouncing attacks
512
513| [16323] OpenSSH scp file overwrite
514
515| [13797] OpenSSH PAM information leak
516
517| [13271] OpenSSH could allow an attacker to corrupt the PAM conversion stack
518
519| [13264] OpenSSH PAM code could allow an attacker to gain access
520
521| [13215] OpenSSH buffer management errors could allow an attacker to execute code
522
523| [13214] OpenSSH memory vulnerabilities
524
525| [13191] OpenSSH large packet buffer overflow
526
527| [12196] OpenSSH could allow an attacker to bypass login restrictions
528
529| [11970] OpenSSH could allow an attacker to obtain valid administrative account
530
531| [11902] OpenSSH PAM support enabled information leak
532
533| [9803] OpenSSH "
534
535| [9763] OpenSSH downloaded from the OpenBSD FTP site or OpenBSD FTP mirror sites could contain a Trojan Horse
536
537| [9307] OpenSSH is running on the system
538
539| [9169] OpenSSH "
540
541| [8896] OpenSSH Kerberos 4 TGT/AFS buffer overflow
542
543| [8697] FreeBSD libutil in OpenSSH fails to drop privileges prior to using the login class capability database
544
545| [8383] OpenSSH off-by-one error in channel code
546
547| [7647] OpenSSH UseLogin option arbitrary code execution
548
549| [7634] OpenSSH using sftp and restricted keypairs could allow an attacker to bypass restrictions
550
551| [7598] OpenSSH with Kerberos allows attacker to gain elevated privileges
552
553| [7179] OpenSSH source IP access control bypass
554
555| [6757] OpenSSH "
556
557| [6676] OpenSSH X11 forwarding symlink attack could allow deletion of arbitrary files
558
559| [6084] OpenSSH 2.3.1 allows remote users to bypass authentication
560
561| [5517] OpenSSH allows unauthorized access to resources
562
563| [4646] OpenSSH UseLogin option allows remote users to execute commands as root
564
565|
566
567| Exploit-DB - http://www.exploit-db.com:
568
569| [3303] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit
570
571| [21579] OpenSSH 3.x Challenge-Response Buffer Overflow Vulnerabilities (2)
572
573| [21578] OpenSSH 3.x Challenge-Response Buffer Overflow Vulnerabilities (1)
574
575| [21402] OpenSSH 2.x/3.x Kerberos 4 TGT/AFS Token Buffer Overflow Vulnerability
576
577| [21314] OpenSSH 2.x/3.0.1/3.0.2 Channel Code Off-By-One Vulnerability
578
579| [20253] OpenSSH 1.2 scp File Create/Overwrite Vulnerability
580
581| [17462] OpenSSH 3.5p1 Remote Root Exploit for FreeBSD
582
583| [14866] Novell Netware v6.5 OpenSSH Remote Stack Overflow
584
585| [6094] Debian OpenSSH Remote SELinux Privilege Elevation Exploit (auth)
586
587| [2444] OpenSSH <= 4.3 p1 (Duplicated Block) Remote Denial of Service Exploit
588
589| [1572] Dropbear / OpenSSH Server (MAX_UNAUTH_CLIENTS) Denial of Service
590
591| [258] glibc-2.2 and openssh-2.3.0p1 exploits glibc >= 2.1.9x
592
593| [26] OpenSSH/PAM <= 3.6.1p1 Remote Users Ident (gossh.sh)
594
595| [25] OpenSSH/PAM <= 3.6.1p1 Remote Users Discovery Tool
596
597|
598
599| OpenVAS (Nessus) - http://www.openvas.org:
600
601| [902488] OpenSSH 'sshd' GSSAPI Credential Disclosure Vulnerability
602
603| [900179] OpenSSH CBC Mode Information Disclosure Vulnerability
604
605| [881183] CentOS Update for openssh CESA-2012:0884 centos6
606
607| [880802] CentOS Update for openssh CESA-2009:1287 centos5 i386
608
609| [880746] CentOS Update for openssh CESA-2009:1470 centos5 i386
610
611| [870763] RedHat Update for openssh RHSA-2012:0884-04
612
613| [870129] RedHat Update for openssh RHSA-2008:0855-01
614
615| [861813] Fedora Update for openssh FEDORA-2010-5429
616
617| [861319] Fedora Update for openssh FEDORA-2007-395
618
619| [861170] Fedora Update for openssh FEDORA-2007-394
620
621| [861012] Fedora Update for openssh FEDORA-2007-715
622
623| [840345] Ubuntu Update for openssh vulnerability USN-597-1
624
625| [840300] Ubuntu Update for openssh update USN-612-5
626
627| [840271] Ubuntu Update for openssh vulnerability USN-612-2
628
629| [840268] Ubuntu Update for openssh update USN-612-7
630
631| [840259] Ubuntu Update for openssh vulnerabilities USN-649-1
632
633| [840214] Ubuntu Update for openssh vulnerability USN-566-1
634
635| [831074] Mandriva Update for openssh MDVA-2010:162 (openssh)
636
637| [830929] Mandriva Update for openssh MDVA-2010:090 (openssh)
638
639| [830807] Mandriva Update for openssh MDVA-2010:026 (openssh)
640
641| [830603] Mandriva Update for openssh MDVSA-2008:098 (openssh)
642
643| [830523] Mandriva Update for openssh MDVSA-2008:078 (openssh)
644
645| [830317] Mandriva Update for openssh-askpass-qt MDKA-2007:127 (openssh-askpass-qt)
646
647| [830191] Mandriva Update for openssh MDKSA-2007:236 (openssh)
648
649| [802407] OpenSSH 'sshd' Challenge Response Authentication Buffer Overflow Vulnerability
650
651| [103503] openssh-server Forced Command Handling Information Disclosure Vulnerability
652
653| [103247] OpenSSH Ciphersuite Specification Information Disclosure Weakness
654
655| [103064] OpenSSH Legacy Certificate Signing Information Disclosure Vulnerability
656
657| [100584] OpenSSH X Connections Session Hijacking Vulnerability
658
659| [100153] OpenSSH CBC Mode Information Disclosure Vulnerability
660
661| [66170] CentOS Security Advisory CESA-2009:1470 (openssh)
662
663| [65987] SLES10: Security update for OpenSSH
664
665| [65819] SLES10: Security update for OpenSSH
666
667| [65514] SLES9: Security update for OpenSSH
668
669| [65513] SLES9: Security update for OpenSSH
670
671| [65334] SLES9: Security update for OpenSSH
672
673| [65248] SLES9: Security update for OpenSSH
674
675| [65218] SLES9: Security update for OpenSSH
676
677| [65169] SLES9: Security update for openssh,openssh-askpass
678
679| [65126] SLES9: Security update for OpenSSH
680
681| [65019] SLES9: Security update for OpenSSH
682
683| [65015] SLES9: Security update for OpenSSH
684
685| [64931] CentOS Security Advisory CESA-2009:1287 (openssh)
686
687| [61639] Debian Security Advisory DSA 1638-1 (openssh)
688
689| [61030] Debian Security Advisory DSA 1576-2 (openssh)
690
691| [61029] Debian Security Advisory DSA 1576-1 (openssh)
692
693| [60840] FreeBSD Security Advisory (FreeBSD-SA-08:05.openssh.asc)
694
695| [60803] Gentoo Security Advisory GLSA 200804-03 (openssh)
696
697| [60667] Slackware Advisory SSA:2008-095-01 openssh
698
699| [59014] Slackware Advisory SSA:2007-255-01 openssh
700
701| [58741] Gentoo Security Advisory GLSA 200711-02 (openssh)
702
703| [57919] Gentoo Security Advisory GLSA 200611-06 (openssh)
704
705| [57895] Gentoo Security Advisory GLSA 200609-17 (openssh)
706
707| [57585] Debian Security Advisory DSA 1212-1 (openssh (1:3.8.1p1-8.sarge.6))
708
709| [57492] Slackware Advisory SSA:2006-272-02 openssh
710
711| [57483] Debian Security Advisory DSA 1189-1 (openssh-krb5)
712
713| [57476] FreeBSD Security Advisory (FreeBSD-SA-06:22.openssh.asc)
714
715| [57470] FreeBSD Ports: openssh
716
717| [56352] FreeBSD Security Advisory (FreeBSD-SA-06:09.openssh.asc)
718
719| [56330] Gentoo Security Advisory GLSA 200602-11 (OpenSSH)
720
721| [56294] Slackware Advisory SSA:2006-045-06 openssh
722
723| [53964] Slackware Advisory SSA:2003-266-01 New OpenSSH packages
724
725| [53885] Slackware Advisory SSA:2003-259-01 OpenSSH Security Advisory
726
727| [53884] Slackware Advisory SSA:2003-260-01 OpenSSH updated again
728
729| [53788] Debian Security Advisory DSA 025-1 (openssh)
730
731| [52638] FreeBSD Security Advisory (FreeBSD-SA-03:15.openssh.asc)
732
733| [52635] FreeBSD Security Advisory (FreeBSD-SA-03:12.openssh.asc)
734
735| [11343] OpenSSH Client Unauthorized Remote Forwarding
736
737| [10954] OpenSSH AFS/Kerberos ticket/token passing
738
739| [10883] OpenSSH Channel Code Off by 1
740
741| [10823] OpenSSH UseLogin Environment Variables
742
743|_
744
74523/tcp filtered telnet
746
74725/tcp open smtp?
748
74980/tcp open http Apache httpd 2.2.31 ((Unix) mod_ssl/2.2.31 OpenSSL/1.0.1e-fips mod_bwlimited/1.4)
750
751|_http-server-header: Apache/2.2.31 (Unix) mod_ssl/2.2.31 OpenSSL/1.0.1e-fips mod_bwlimited/1.4
752
753| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
754
755| [4527] Apache Struts up to 2.2.3.1 ExceptionDelegator Code Injection
756
757| [2452] Apache httpd up to 2.2.3 on Windows mod_alias Designfehler
758
759| [2414] Apache httpd up to 2.2.3 mod_rewrite buffer overflow
760
761| [9891] Apache HTTP Server 2.2.22 suEXEC Feature .htaccess information disclosure
762
763| [4583] Apache httpd up to 2.2.21 Threaded MPM denial of service
764
765| [4582] Apache httpd up to 2.2.21 protocol.c information disclosure
766
767| [4352] Apache httpd 2.2.x APR apr_fnmatch() denial of service
768
769| [2393] Apache httpd up to 2.2.2 HTTP Header Handler Expect-Header cross site scripting
770
771|
772
773| MITRE CVE - http://cve.mitre.org:
774
775| [CVE-2012-1006] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
776
777| [CVE-2012-0838] Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
778
779| [CVE-2012-0391] The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
780
781| [CVE-2011-2087] Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
782
783| [CVE-2011-1772] Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
784
785| [CVE-2007-1743] suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
786
787| [CVE-2007-1742] suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
788
789| [CVE-2007-1741] Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
790
791| [CVE-2013-1896] mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
792
793| [CVE-2013-1862] mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
794
795| [CVE-2013-1768] The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
796
797| [CVE-2013-1048] The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
798
799| [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
800
801| [CVE-2012-4557] The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
802
803| [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
804
805| [CVE-2012-0216] The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
806
807| [CVE-2012-0053] protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
808
809| [CVE-2012-0031] scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
810
811| [CVE-2012-0021] The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
812
813| [CVE-2011-5034] Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
814
815| [CVE-2011-4668] IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
816
817| [CVE-2011-4415] The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
818
819| [CVE-2011-4317] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
820
821| [CVE-2011-3639] The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
822
823| [CVE-2011-3607] Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.
824
825| [CVE-2011-3368] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
826
827| [CVE-2011-3348] The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
828
829| [CVE-2011-3192] The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
830
831| [CVE-2011-2088] XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
832
833| [CVE-2011-1928] The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.
834
835| [CVE-2011-1176] The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
836
837| [CVE-2011-0419] Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
838
839| [CVE-2010-4476] The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
840
841| [CVE-2010-2791] mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
842
843| [CVE-2010-2076] Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
844
845| [CVE-2010-2068] mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.
846
847| [CVE-2010-1452] The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
848
849| [CVE-2010-0434] The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
850
851| [CVE-2010-0425] modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
852
853| [CVE-2010-0408] The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
854
855| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
856
857| [CVE-2009-3094] The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
858
859| [CVE-2009-2699] The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
860
861| [CVE-2009-1891] The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
862
863| [CVE-2009-1195] The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
864
865| [CVE-2009-1191] mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
866
867| [CVE-2008-3666] Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured
868
869| [CVE-2008-2939] Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
870
871| [CVE-2008-2364] The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
872
873| [CVE-2008-2168] Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
874
875| [CVE-2008-0456] CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
876
877| [CVE-2008-0455] Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
878
879| [CVE-2008-0005] mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
880
881| [CVE-2007-6750] The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
882
883| [CVE-2007-6423] ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
884
885| [CVE-2007-6422] The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
886
887| [CVE-2007-6421] Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
888
889| [CVE-2007-6420] Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
890
891| [CVE-2007-6388] Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
892
893| [CVE-2007-6203] Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
894
895| [CVE-2007-5000] Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
896
897| [CVE-2007-4465] Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
898
899| [CVE-2007-3304] Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
900
901| [CVE-2007-3303] Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
902
903| [CVE-2007-1862] The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
904
905| [CVE-2007-0792] The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
906
907| [CVE-2006-4110] Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
908
909| [CVE-2006-3918] http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
910
911| [CVE-2006-3747] Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
912
913| [CVE-2006-2806] The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.
914
915| [CVE-2006-1292] Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
916
917| [CVE-2006-1079] htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
918
919| [CVE-2006-1078] Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
920
921| [CVE-2004-2650] Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
922
923| [CVE-2003-1172] Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
924
925| [CVE-2002-1233] A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
926
927|
928
929| OSVDB - http://www.osvdb.org:
930
931| [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
932
933|
934
935| SecurityFocus - http://www.securityfocus.com/bid/:
936
937| [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
938
939| [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
940
941|
942
943| SecurityTracker - http://www.securitytracker.com:
944
945| [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
946
947| [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
948
949| [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
950
951| [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
952
953| [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
954
955|
956
957| IBM X-Force - http://xforce.iss.net:
958
959| [75211] Debian GNU/Linux apache 2 cross-site scripting
960
961|
962
963| Exploit-DB - http://www.exploit-db.com:
964
965| [18329] Apache Struts2 <= 2.3.1 Multiple Vulnerabilities
966
967|
968
969| OpenVAS (Nessus) - http://www.openvas.org:
970
971| [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
972
973|_
974
975110/tcp open pop3 Dovecot pop3d
976
977| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
978
979| [9807] Dovecot up to 1.2.7 on Exim Input Sanitizer MAIL FROM privilege escalation
980
981| [7062] Dovecot 2.1.10 lib-storage/mail-search.c denial of service
982
983|
984
985| MITRE CVE - http://cve.mitre.org:
986
987| [CVE-2011-4318] Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
988
989| [CVE-2011-2167] script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
990
991| [CVE-2011-2166] script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
992
993| [CVE-2011-1929] lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
994
995| [CVE-2010-4011] Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
996
997| [CVE-2010-3780] Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
998
999| [CVE-2010-3779] Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
1000
1001| [CVE-2010-3707] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
1002
1003| [CVE-2010-3706] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
1004
1005| [CVE-2010-3304] The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
1006
1007| [CVE-2010-0745] Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.
1008
1009| [CVE-2010-0535] Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
1010
1011| [CVE-2010-0433] The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
1012
1013| [CVE-2009-3897] Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
1014
1015| [CVE-2009-3235] Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
1016
1017| [CVE-2009-2632] Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
1018
1019| [CVE-2008-5301] Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
1020
1021| [CVE-2008-4907] The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
1022
1023| [CVE-2008-4870] dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
1024
1025| [CVE-2008-4578] The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
1026
1027| [CVE-2008-4577] The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
1028
1029| [CVE-2008-1218] Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.
1030
1031| [CVE-2008-1199] Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
1032
1033| [CVE-2007-6598] Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
1034
1035| [CVE-2007-5794] Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
1036
1037| [CVE-2007-4211] The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
1038
1039| [CVE-2007-2231] Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
1040
1041| [CVE-2007-2173] Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
1042
1043| [CVE-2007-0618] Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
1044
1045| [CVE-2006-5973] Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
1046
1047| [CVE-2006-2502] Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
1048
1049| [CVE-2006-2414] Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
1050
1051| [CVE-2006-0730] Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
1052
1053| [CVE-2002-0925] Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.
1054
1055| [CVE-2001-0143] vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.
1056
1057| [CVE-2000-1197] POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.
1058
1059| [CVE-1999-1445] Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.
1060
1061|
1062
1063| OSVDB - http://www.osvdb.org:
1064
1065| [96172] Dovecot POP3 Service Terminated LIST Command Remote DoS
1066
1067| [93525] Dovecot IMAP APPEND Command Malformed Parameter Parsing Remote DoS
1068
1069| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
1070
1071| [88058] Dovecot lib-storage/mail-search.c Multiple Keyword Search Handling Remote DoS
1072
1073| [77185] Dovecot SSL Certificate Common Name Field MitM Spoofing Weakness
1074
1075| [74515] Dovecot script-login chroot Configuration Setting Traversal Arbitrary File Access
1076
1077| [74514] Dovecot script-login User / Group Configuration Settings Remote Access Restriction Bypass
1078
1079| [72495] Dovecot lib-mail/message-header-parser.c Mail Header Name NULL Character Handling Remote DoS
1080
1081| [69260] Apple Mac OS X Server Dovecot Memory Aliasing Mail Delivery Issue
1082
1083| [68516] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition User Private Namespace Mailbox Access Restriction Remote Bypass
1084
1085| [68515] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition Specific Entry Order Mailbox Access Restriction Remote Bypass
1086
1087| [68513] Dovecot Non-public Namespace Mailbox ACL Manipulation Access Restriction Remote Bypass
1088
1089| [68512] Dovecot IMAP / POP3 Session Disconnect Master Process Outage Remote DoS
1090
1091| [66625] Dovecot ACL Plugin INBOX ACL Copying Weakness Restriction Bypass
1092
1093| [66113] Dovecot Mail Root Directory Creation Permission Weakness
1094
1095| [66112] Dovecot Installation base_dir Parent Directory Permission Weakness
1096
1097| [66111] Dovecot SEARCH Functionality str_find_init() Function Overflow
1098
1099| [66110] Dovecot Multiple Unspecified Buffer Overflows
1100
1101| [66108] Dovecot Malformed Message Body Processing Unspecified Functions Remote DoS
1102
1103| [64783] Dovecot E-mail Message Header Unspecified DoS
1104
1105| [63372] Apple Mac OS X Dovecot Kerberos Authentication SACL Restriction Bypass
1106
1107| [62796] Dovecot mbox Format Email Header Handling DoS
1108
1109| [60316] Dovecot base_dir Directory Permission Weakness Local Privilege Escalation
1110
1111| [58103] Dovecot CMU Sieve Plugin Script Handling Multiple Overflows
1112
1113| [50253] Dovecot dovecot.conf Permission Weakness Local ssl_key_password Parameter Disclosure
1114
1115| [49918] Dovecot ManageSieve Script Name Handling Traversal Arbitrary File Manipulation
1116
1117| [49429] Dovecot Message Parsing Feature Crafted Email Header Handling Remote DoS
1118
1119| [49099] Dovecot ACL Plugin k Right Mailbox Creation Restriction Bypass
1120
1121| [49098] Dovecot ACL Plugin Negative Access Rights Bypass
1122
1123| [43137] Dovecot mail_extra_groups Symlink File Manipulation
1124
1125| [42979] Dovecot passdbs Argument Injection Authentication Bypass
1126
1127| [39876] Dovecot LDAP Auth Cache Security Bypass
1128
1129| [39386] Dovecot ACL Plugin Insert Right APPEND / COPY Command Unauthorized Flag Manipulation
1130
1131| [35489] Dovecot index/mbox/mbox-storage.c Traversal Arbitrary Gzip File Access
1132
1133| [30524] Dovecot IMAP/POP3 Server dovecot.index.cache Handling Overflow
1134
1135| [25853] Cyrus IMAPD pop3d USER Command Remote Overflow
1136
1137| [25727] Dovecot Multiple Command Traversal Arbitrary Directory Listing
1138
1139| [23281] Dovecot imap/pop3-login dovecot-auth DoS
1140
1141| [23280] Dovecot Malformed APPEND Command DoS
1142
1143| [14459] mmmail mmpop3d USER Command mmsyslog Function Format String
1144
1145| [12033] Slackware Linux imapd/ipop3d Malformed USER/PASS Sequence DoS
1146
1147| [5857] Linux pop3d Arbitrary Mail File Access
1148
1149| [2471] akpop3d username SQL Injection
1150
1151|
1152
1153| SecurityFocus - http://www.securityfocus.com/bid/:
1154
1155| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
1156
1157| [60052] Dovecot 'APPEND' Parameter Denial of Service Vulnerability
1158
1159| [56759] RETIRED: Dovecot 'mail-search.c' Denial of Service Vulnerability
1160
1161| [50709] Dovecot SSL Certificate 'Common Name' Field Validation Security Bypass Vulnerability
1162
1163| [48003] Dovecot 'script-login' Multiple Security Bypass Vulnerabilities
1164
1165| [47930] Dovecot Header Name NULL Character Denial of Service Vulnerability
1166
1167| [44874] Apple Mac OS X Dovecot (CVE-2010-4011) Memory Corruption Vulnerability
1168
1169| [43690] Dovecot Access Control List (ACL) Multiple Remote Vulnerabilities
1170
1171| [41964] Dovecot Access Control List (ACL) Plugin Security Bypass Weakness
1172
1173| [39838] tpop3d Remote Denial of Service Vulnerability
1174
1175| [39258] Dovecot Service Control Access List Security Bypass Vulnerability
1176
1177| [37084] Dovecot Insecure 'base_dir' Permissions Local Privilege Escalation Vulnerability
1178
1179| [36377] Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
1180
1181| [32582] Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
1182
1183| [31997] Dovecot Invalid Message Address Parsing Denial of Service Vulnerability
1184
1185| [31587] Dovecot ACL Plugin Multiple Security Bypass Vulnerabilities
1186
1187| [28181] Dovecot 'Tab' Character Password Check Security Bypass Vulnerability
1188
1189| [28092] Dovecot 'mail_extra_groups' Insecure Settings Local Unauthorized Access Vulnerability
1190
1191| [27093] Dovecot Authentication Cache Security Bypass Vulnerability
1192
1193| [25182] Dovecot ACL Plugin Security Bypass Vulnerability
1194
1195| [23552] Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
1196
1197| [22262] IBM AIX Pop3D/Pop3DS/IMapD/IMapDS Authentication Bypass Vulnerability
1198
1199| [21183] Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
1200
1201| [18056] Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
1202
1203| [17961] Dovecot Remote Information Disclosure Vulnerability
1204
1205| [16672] Dovecot Double Free Denial of Service Vulnerability
1206
1207| [8495] akpop3d User Name SQL Injection Vulnerability
1208
1209| [8473] Vpop3d Remote Denial Of Service Vulnerability
1210
1211| [3990] ZPop3D Bad Login Logging Failure Vulnerability
1212
1213| [2781] DynFX MailServer POP3d Denial of Service Vulnerability
1214
1215|
1216
1217| SecurityTracker - http://www.securitytracker.com:
1218
1219| [1028585] Dovecot APPEND Parameter Processing Flaw Lets Remote Authenticated Users Deny Service
1220
1221| [1024740] Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User
1222
1223| [1017288] Dovecot POP3/IMAP Cache File Buffer Overflow May Let Remote Users Execute Arbitrary Code
1224
1225|
1226
1227| IBM X-Force - http://xforce.iss.net:
1228
1229| [86382] Dovecot POP3 Service denial of service
1230
1231| [84396] Dovecot IMAP APPEND denial of service
1232
1233| [80453] Dovecot mail-search.c denial of service
1234
1235| [71354] Dovecot SSL Common Name (CN) weak security
1236
1237| [67675] Dovecot script-login security bypass
1238
1239| [67674] Dovecot script-login directory traversal
1240
1241| [67589] Dovecot header name denial of service
1242
1243| [63267] Apple Mac OS X Dovecot information disclosure
1244
1245| [62340] Dovecot mailbox security bypass
1246
1247| [62339] Dovecot IMAP or POP3 denial of service
1248
1249| [62256] Dovecot mailbox security bypass
1250
1251| [62255] Dovecot ACL entry security bypass
1252
1253| [60639] Dovecot ACL plugin weak security
1254
1255| [57267] Apple Mac OS X Dovecot Kerberos security bypass
1256
1257| [56763] Dovecot header denial of service
1258
1259| [54363] Dovecot base_dir privilege escalation
1260
1261| [53248] CMU Sieve plugin for Dovecot unspecified buffer overflow
1262
1263| [46323] Dovecot dovecot.conf information disclosure
1264
1265| [46227] Dovecot message parsing denial of service
1266
1267| [45669] Dovecot ACL mailbox security bypass
1268
1269| [45667] Dovecot ACL plugin rights security bypass
1270
1271| [41085] Dovecot TAB characters authentication bypass
1272
1273| [41009] Dovecot mail_extra_groups option unauthorized access
1274
1275| [39342] Dovecot LDAP auth cache configuration security bypass
1276
1277| [35767] Dovecot ACL plugin security bypass
1278
1279| [34082] Dovecot mbox-storage.c directory traversal
1280
1281| [30433] Dovecot IMAP/POP3 server dovecot.index.cache buffer overflow
1282
1283| [26578] Cyrus IMAP pop3d buffer overflow
1284
1285| [26536] Dovecot IMAP LIST information disclosure
1286
1287| [24710] Dovecot dovecot-auth and imap/pop3-login denial of service
1288
1289| [24709] Dovecot APPEND command denial of service
1290
1291| [13018] akpop3d authentication code SQL injection
1292
1293| [7345] Slackware Linux imapd and ipop3d core dump
1294
1295| [6269] imap, ipop2d and ipop3d buffer overflows
1296
1297| [5923] Linuxconf vpop3d symbolic link
1298
1299| [4918] IPOP3D, Buffer overflow attack
1300
1301| [1560] IPOP3D, user login successful
1302
1303| [1559] IPOP3D user login to remote host successful
1304
1305| [1525] IPOP3D, user logout
1306
1307| [1524] IPOP3D, user auto-logout
1308
1309| [1523] IPOP3D, user login failure
1310
1311| [1522] IPOP3D, brute force attack
1312
1313| [1521] IPOP3D, user kiss of death logout
1314
1315| [418] pop3d mktemp creates insecure temporary files
1316
1317|
1318
1319| Exploit-DB - http://www.exploit-db.com:
1320
1321| [25297] Dovecot with Exim sender_address Parameter - Remote Command Execution
1322
1323| [23053] Vpop3d Remote Denial Of Service Vulnerability
1324
1325| [16836] Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
1326
1327| [11893] tPop3d 1.5.3 DoS
1328
1329| [5257] Dovecot IMAP 1.0.10 <= 1.1rc2 Remote Email Disclosure Exploit
1330
1331| [2185] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (3)
1332
1333| [2053] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (2)
1334
1335| [1813] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit
1336
1337|
1338
1339| OpenVAS (Nessus) - http://www.openvas.org:
1340
1341| [901026] Dovecot Sieve Plugin Multiple Buffer Overflow Vulnerabilities
1342
1343| [901025] Dovecot Version Detection
1344
1345| [881402] CentOS Update for dovecot CESA-2011:1187 centos5 x86_64
1346
1347| [881358] CentOS Update for dovecot CESA-2011:1187 centos4 x86_64
1348
1349| [880980] CentOS Update for dovecot CESA-2011:1187 centos5 i386
1350
1351| [880967] CentOS Update for dovecot CESA-2011:1187 centos4 i386
1352
1353| [870607] RedHat Update for dovecot RHSA-2011:0600-01
1354
1355| [870471] RedHat Update for dovecot RHSA-2011:1187-01
1356
1357| [870153] RedHat Update for dovecot RHSA-2008:0297-02
1358
1359| [863272] Fedora Update for dovecot FEDORA-2011-7612
1360
1361| [863115] Fedora Update for dovecot FEDORA-2011-7258
1362
1363| [861525] Fedora Update for dovecot FEDORA-2007-664
1364
1365| [861394] Fedora Update for dovecot FEDORA-2007-493
1366
1367| [861333] Fedora Update for dovecot FEDORA-2007-1485
1368
1369| [860845] Fedora Update for dovecot FEDORA-2008-9202
1370
1371| [860663] Fedora Update for dovecot FEDORA-2008-2475
1372
1373| [860169] Fedora Update for dovecot FEDORA-2008-2464
1374
1375| [860089] Fedora Update for dovecot FEDORA-2008-9232
1376
1377| [840950] Ubuntu Update for dovecot USN-1295-1
1378
1379| [840668] Ubuntu Update for dovecot USN-1143-1
1380
1381| [840583] Ubuntu Update for dovecot vulnerabilities USN-1059-1
1382
1383| [840335] Ubuntu Update for dovecot vulnerabilities USN-593-1
1384
1385| [840290] Ubuntu Update for dovecot vulnerability USN-567-1
1386
1387| [840234] Ubuntu Update for dovecot vulnerability USN-666-1
1388
1389| [840072] Ubuntu Update for dovecot vulnerability USN-487-1
1390
1391| [831405] Mandriva Update for dovecot MDVSA-2011:101 (dovecot)
1392
1393| [831230] Mandriva Update for dovecot MDVSA-2010:217 (dovecot)
1394
1395| [831197] Mandriva Update for dovecot MDVSA-2010:196 (dovecot)
1396
1397| [831054] Mandriva Update for dovecot MDVSA-2010:104 (dovecot)
1398
1399| [830496] Mandriva Update for dovecot MDVSA-2008:232 (dovecot)
1400
1401| [801055] Dovecot 'base_dir' Insecure Permissions Security Bypass Vulnerability
1402
1403| [800030] Dovecot ACL Plugin Security Bypass Vulnerabilities
1404
1405| [70767] Gentoo Security Advisory GLSA 201110-04 (Dovecot)
1406
1407| [70259] FreeBSD Ports: dovecot
1408
1409| [69959] Debian Security Advisory DSA 2252-1 (dovecot)
1410
1411| [66522] FreeBSD Ports: dovecot
1412
1413| [65010] Ubuntu USN-838-1 (dovecot)
1414
1415| [64978] Debian Security Advisory DSA 1892-1 (dovecot)
1416
1417| [64953] Mandrake Security Advisory MDVSA-2009:242-1 (dovecot)
1418
1419| [64952] Mandrake Security Advisory MDVSA-2009:242 (dovecot)
1420
1421| [64861] Fedora Core 10 FEDORA-2009-9559 (dovecot)
1422
1423| [62965] Gentoo Security Advisory GLSA 200812-16 (dovecot)
1424
1425| [62854] FreeBSD Ports: dovecot-managesieve
1426
1427| [61916] FreeBSD Ports: dovecot
1428
1429| [60588] Gentoo Security Advisory GLSA 200803-25 (dovecot)
1430
1431| [60568] Debian Security Advisory DSA 1516-1 (dovecot)
1432
1433| [60528] FreeBSD Ports: dovecot
1434
1435| [60134] Debian Security Advisory DSA 1457-1 (dovecot)
1436
1437| [60089] FreeBSD Ports: dovecot
1438
1439| [58578] Debian Security Advisory DSA 1359-1 (dovecot)
1440
1441| [56834] Debian Security Advisory DSA 1080-1 (dovecot)
1442
1443|_
1444
1445111/tcp filtered rpcbind
1446
1447113/tcp filtered ident
1448
1449135/tcp filtered msrpc
1450
1451139/tcp filtered netbios-ssn
1452
1453143/tcp open imap Dovecot imapd
1454
1455| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
1456
1457| [9807] Dovecot up to 1.2.7 on Exim Input Sanitizer MAIL FROM privilege escalation
1458
1459| [7062] Dovecot 2.1.10 lib-storage/mail-search.c denial of service
1460
1461|
1462
1463| MITRE CVE - http://cve.mitre.org:
1464
1465| [CVE-2009-2632] Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
1466
1467| [CVE-2011-4318] Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
1468
1469| [CVE-2011-3481] The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.
1470
1471| [CVE-2011-3372] imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
1472
1473| [CVE-2011-2167] script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
1474
1475| [CVE-2011-2166] script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
1476
1477| [CVE-2011-1929] lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
1478
1479| [CVE-2010-4011] Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
1480
1481| [CVE-2010-3780] Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
1482
1483| [CVE-2010-3779] Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
1484
1485| [CVE-2010-3707] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
1486
1487| [CVE-2010-3706] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
1488
1489| [CVE-2010-3304] The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
1490
1491| [CVE-2010-0745] Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.
1492
1493| [CVE-2010-0535] Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
1494
1495| [CVE-2010-0433] The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
1496
1497| [CVE-2009-3897] Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
1498
1499| [CVE-2009-3235] Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
1500
1501| [CVE-2008-5301] Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
1502
1503| [CVE-2008-4907] The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
1504
1505| [CVE-2008-4870] dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
1506
1507| [CVE-2008-4578] The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
1508
1509| [CVE-2008-4577] The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
1510
1511| [CVE-2008-1218] Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.
1512
1513| [CVE-2008-1199] Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
1514
1515| [CVE-2007-6598] Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
1516
1517| [CVE-2007-5794] Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
1518
1519| [CVE-2007-5740] The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.
1520
1521| [CVE-2007-5018] Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.
1522
1523| [CVE-2007-4211] The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
1524
1525| [CVE-2007-3925] Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.
1526
1527| [CVE-2007-2231] Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
1528
1529| [CVE-2007-2173] Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
1530
1531| [CVE-2007-1579] Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command.
1532
1533| [CVE-2007-1578] Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.
1534
1535| [CVE-2007-0618] Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
1536
1537| [CVE-2006-6762] The IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to cause a denial of service via an APPEND command with a single "(" (parenthesis) in the argument.
1538
1539| [CVE-2006-6761] Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via a long argument to the SUBSCRIBE command.
1540
1541| [CVE-2006-6425] Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via unspecified vectors involving the APPEND command.
1542
1543| [CVE-2006-6424] Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow
1544
1545| [CVE-2006-5973] Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
1546
1547| [CVE-2006-2502] Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
1548
1549| [CVE-2006-2414] Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
1550
1551| [CVE-2006-0730] Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
1552
1553| [CVE-2005-2278] Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.
1554
1555| [CVE-2005-1256] Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.
1556
1557| [CVE-2005-1249] The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop.
1558
1559| [CVE-2005-1015] Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
1560
1561| [CVE-2005-0546] Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapd annotate extension, (2) an off-by-one error in "cached header handling," (3) a stack-based buffer overflow in fetchnews, or (4) a stack-based buffer overflow in imapd.
1562
1563| [CVE-2003-1322] Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10) CREATE, or (11) SELECT command.
1564
1565| [CVE-2002-1782] The default configuration of University of Washington IMAP daemon (wu-imapd), when running on a system that does not allow shell access, allows a local user with a valid IMAP account to read arbitrary files as that user.
1566
1567| [CVE-2002-1604] Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver.
1568
1569| [CVE-2002-0997] Buffer overflows in IMAP Agent (imapd) for Novell NetMail (NIMS) 3.0.3 before 3.0.3A allows remote attackers to cause a denial of service.
1570
1571| [CVE-2002-0379] Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and earlier, allows remote authenticated users to execute arbitrary code via a long BODY request.
1572
1573| [CVE-2001-0691] Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.
1574
1575| [CVE-2000-0284] Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.
1576
1577| [CVE-1999-1557] Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.
1578
1579| [CVE-1999-1445] Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.
1580
1581| [CVE-1999-1224] IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information.
1582
1583|
1584
1585| OSVDB - http://www.osvdb.org:
1586
1587| [96172] Dovecot POP3 Service Terminated LIST Command Remote DoS
1588
1589| [93525] Dovecot IMAP APPEND Command Malformed Parameter Parsing Remote DoS
1590
1591| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
1592
1593| [88058] Dovecot lib-storage/mail-search.c Multiple Keyword Search Handling Remote DoS
1594
1595| [78304] Eudora WorldMail imapd SEH LIST Command Parsing Remote Overflow
1596
1597| [77185] Dovecot SSL Certificate Common Name Field MitM Spoofing Weakness
1598
1599| [75445] Cyrus IMAP Server imapd index.c index_get_ids Function References Header NULL Dereference Remote DoS
1600
1601| [74515] Dovecot script-login chroot Configuration Setting Traversal Arbitrary File Access
1602
1603| [74514] Dovecot script-login User / Group Configuration Settings Remote Access Restriction Bypass
1604
1605| [72495] Dovecot lib-mail/message-header-parser.c Mail Header Name NULL Character Handling Remote DoS
1606
1607| [69260] Apple Mac OS X Server Dovecot Memory Aliasing Mail Delivery Issue
1608
1609| [68516] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition User Private Namespace Mailbox Access Restriction Remote Bypass
1610
1611| [68515] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition Specific Entry Order Mailbox Access Restriction Remote Bypass
1612
1613| [68513] Dovecot Non-public Namespace Mailbox ACL Manipulation Access Restriction Remote Bypass
1614
1615| [68512] Dovecot IMAP / POP3 Session Disconnect Master Process Outage Remote DoS
1616
1617| [66625] Dovecot ACL Plugin INBOX ACL Copying Weakness Restriction Bypass
1618
1619| [66113] Dovecot Mail Root Directory Creation Permission Weakness
1620
1621| [66112] Dovecot Installation base_dir Parent Directory Permission Weakness
1622
1623| [66111] Dovecot SEARCH Functionality str_find_init() Function Overflow
1624
1625| [66110] Dovecot Multiple Unspecified Buffer Overflows
1626
1627| [66108] Dovecot Malformed Message Body Processing Unspecified Functions Remote DoS
1628
1629| [64783] Dovecot E-mail Message Header Unspecified DoS
1630
1631| [63372] Apple Mac OS X Dovecot Kerberos Authentication SACL Restriction Bypass
1632
1633| [62796] Dovecot mbox Format Email Header Handling DoS
1634
1635| [60316] Dovecot base_dir Directory Permission Weakness Local Privilege Escalation
1636
1637| [58103] Dovecot CMU Sieve Plugin Script Handling Multiple Overflows
1638
1639| [57843] Cyrus IMAP Server (cyrus-imapd) SIEVE Script Component (sieve/script.c) Crafted Script Handling Overflow
1640
1641| [57681] UoW imap Server (uw-imapd) Arbitrary Remote File Access
1642
1643| [52906] UW-imapd c-client Initial Request Remote Format String
1644
1645| [52905] UW-imapd c-client Library RFC822BUFFER Routines rfc822_output_char Function Off-by-one
1646
1647| [52456] UW-imapd on Debian Linux LOGIN Command Remote DoS
1648
1649| [50253] Dovecot dovecot.conf Permission Weakness Local ssl_key_password Parameter Disclosure
1650
1651| [49918] Dovecot ManageSieve Script Name Handling Traversal Arbitrary File Manipulation
1652
1653| [49485] UW-imapd dmail Utility Mailbox Name Handling Overflow
1654
1655| [49484] UW-imapd tmail Utility Mailbox Name Handling Overflow
1656
1657| [49429] Dovecot Message Parsing Feature Crafted Email Header Handling Remote DoS
1658
1659| [49099] Dovecot ACL Plugin k Right Mailbox Creation Restriction Bypass
1660
1661| [49098] Dovecot ACL Plugin Negative Access Rights Bypass
1662
1663| [43137] Dovecot mail_extra_groups Symlink File Manipulation
1664
1665| [42979] Dovecot passdbs Argument Injection Authentication Bypass
1666
1667| [42004] Perdition Mail Retrieval Proxy IMAPD IMAP Tag Remote Format String Arbitrary Code Execution
1668
1669| [39876] Dovecot LDAP Auth Cache Security Bypass
1670
1671| [39670] Mercury Mail Transport System IMAPD SEARCH Command Remote Overflow
1672
1673| [39386] Dovecot ACL Plugin Insert Right APPEND / COPY Command Unauthorized Flag Manipulation
1674
1675| [35489] Dovecot index/mbox/mbox-storage.c Traversal Arbitrary Gzip File Access
1676
1677| [31362] Novell NetMail IMAP Daemon (IMAPD) APPEND Command Remote Overflow
1678
1679| [31361] Novell NetMail IMAP Daemon (IMAPD) APPEND Command DoS
1680
1681| [31360] Novell NetMail IMAP Daemon (IMAPD) SUBSCRIBE Command Remote Overflow
1682
1683| [30524] Dovecot IMAP/POP3 Server dovecot.index.cache Handling Overflow
1684
1685| [25853] Cyrus IMAPD pop3d USER Command Remote Overflow
1686
1687| [25727] Dovecot Multiple Command Traversal Arbitrary Directory Listing
1688
1689| [23281] Dovecot imap/pop3-login dovecot-auth DoS
1690
1691| [23280] Dovecot Malformed APPEND Command DoS
1692
1693| [18179] HP Tru64 UNIX imapd NLSPATH Environment Variable Local Overflow
1694
1695| [13242] UW-imapd CRAM-MD5 Authentication Bypass
1696
1697| [12385] Novell NetMail IMAPD 101_mEna Script Remote Overflow
1698
1699| [12042] UoW imapd Multiple Unspecified Overflows
1700
1701| [12037] UoW imapd (UW-IMAP) Multiple Command Remote Overflows
1702
1703| [12033] Slackware Linux imapd/ipop3d Malformed USER/PASS Sequence DoS
1704
1705| [911] UoW imapd AUTHENTICATE Command Remote Overflow
1706
1707| [790] UoW imap Server (uw-imapd) BODY Request Remote Overflow
1708
1709| [519] UoW imapd SIGABRT Signal Forced Crash Information Disclosure
1710
1711|
1712
1713| SecurityFocus - http://www.securityfocus.com/bid/:
1714
1715| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
1716
1717| [60052] Dovecot 'APPEND' Parameter Denial of Service Vulnerability
1718
1719| [56759] RETIRED: Dovecot 'mail-search.c' Denial of Service Vulnerability
1720
1721| [51403] Eudora WorldMail imapd 'LIST' Command Buffer Overflow Vulnerability
1722
1723| [50709] Dovecot SSL Certificate 'Common Name' Field Validation Security Bypass Vulnerability
1724
1725| [49949] Cyrus IMAPd NTTP Logic Error Authentication Bypass Vulnerability
1726
1727| [48003] Dovecot 'script-login' Multiple Security Bypass Vulnerabilities
1728
1729| [47930] Dovecot Header Name NULL Character Denial of Service Vulnerability
1730
1731| [44874] Apple Mac OS X Dovecot (CVE-2010-4011) Memory Corruption Vulnerability
1732
1733| [43690] Dovecot Access Control List (ACL) Multiple Remote Vulnerabilities
1734
1735| [41964] Dovecot Access Control List (ACL) Plugin Security Bypass Weakness
1736
1737| [39258] Dovecot Service Control Access List Security Bypass Vulnerability
1738
1739| [37084] Dovecot Insecure 'base_dir' Permissions Local Privilege Escalation Vulnerability
1740
1741| [36377] Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
1742
1743| [32582] Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
1744
1745| [31997] Dovecot Invalid Message Address Parsing Denial of Service Vulnerability
1746
1747| [31587] Dovecot ACL Plugin Multiple Security Bypass Vulnerabilities
1748
1749| [28181] Dovecot 'Tab' Character Password Check Security Bypass Vulnerability
1750
1751| [28092] Dovecot 'mail_extra_groups' Insecure Settings Local Unauthorized Access Vulnerability
1752
1753| [27093] Dovecot Authentication Cache Security Bypass Vulnerability
1754
1755| [26270] Perdition IMAPD __STR_VWRITE Remote Format String Vulnerability
1756
1757| [25733] Mercury/32 IMAPD SEARCH Command Remote Stack Buffer Overflow Vulnerability
1758
1759| [25182] Dovecot ACL Plugin Security Bypass Vulnerability
1760
1761| [23552] Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
1762
1763| [23058] Atrium Mercur IMapD NTLM Buffer Overflow Vulnerability
1764
1765| [22262] IBM AIX Pop3D/Pop3DS/IMapD/IMapDS Authentication Bypass Vulnerability
1766
1767| [21183] Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
1768
1769| [18056] Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
1770
1771| [17961] Dovecot Remote Information Disclosure Vulnerability
1772
1773| [16672] Dovecot Double Free Denial of Service Vulnerability
1774
1775| [15980] Qualcomm WorldMail IMAPD Buffer Overflow Vulnerability
1776
1777| [15753] Ipswitch Collaboration Suite and IMail Server IMAPD LIST Command Denial Of Service Vulnerability
1778
1779| [12636] Cyrus IMAPD Multiple Remote Buffer Overflow Vulnerabilities
1780
1781| [11738] Cyrus IMAPD Multiple Remote Unspecified Vulnerabilities
1782
1783| [11729] Cyrus IMAPD Multiple Remote Vulnerabilities
1784
1785| [6298] Cyrus IMAPD Pre-Login Heap Corruption Vulnerability
1786
1787| [4713] Wu-imapd Partial Mailbox Attribute Remote Buffer Overflow Vulnerability
1788
1789| [2856] Imapd 'Local' Buffer Overflow Vulnerabilities
1790
1791| [1110] Univ. Of Washington imapd Buffer Overflow Vulnerabilities
1792
1793| [502] NT IMail Imapd Buffer Overflow DoS Vulnerability
1794
1795| [130] imapd Buffer Overflow Vulnerability
1796
1797|
1798
1799| SecurityTracker - http://www.securitytracker.com:
1800
1801| [1028585] Dovecot APPEND Parameter Processing Flaw Lets Remote Authenticated Users Deny Service
1802
1803| [1024740] Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User
1804
1805| [1017288] Dovecot POP3/IMAP Cache File Buffer Overflow May Let Remote Users Execute Arbitrary Code
1806
1807| [1013278] Cyrus IMAPd Buffer Overflows in Annotate Extension, Cached Header, and Fetchnews May Let Remote Users Execute Arbitrary Code
1808
1809|
1810
1811| IBM X-Force - http://xforce.iss.net:
1812
1813| [86382] Dovecot POP3 Service denial of service
1814
1815| [84396] Dovecot IMAP APPEND denial of service
1816
1817| [80453] Dovecot mail-search.c denial of service
1818
1819| [71354] Dovecot SSL Common Name (CN) weak security
1820
1821| [70325] Cyrus IMAPd NNTP security bypass
1822
1823| [67675] Dovecot script-login security bypass
1824
1825| [67674] Dovecot script-login directory traversal
1826
1827| [67589] Dovecot header name denial of service
1828
1829| [63267] Apple Mac OS X Dovecot information disclosure
1830
1831| [62340] Dovecot mailbox security bypass
1832
1833| [62339] Dovecot IMAP or POP3 denial of service
1834
1835| [62256] Dovecot mailbox security bypass
1836
1837| [62255] Dovecot ACL entry security bypass
1838
1839| [60639] Dovecot ACL plugin weak security
1840
1841| [57267] Apple Mac OS X Dovecot Kerberos security bypass
1842
1843| [56763] Dovecot header denial of service
1844
1845| [54363] Dovecot base_dir privilege escalation
1846
1847| [53248] CMU Sieve plugin for Dovecot unspecified buffer overflow
1848
1849| [47526] UW-imapd rfc822_output_char() denial of service
1850
1851| [46323] Dovecot dovecot.conf information disclosure
1852
1853| [46227] Dovecot message parsing denial of service
1854
1855| [45669] Dovecot ACL mailbox security bypass
1856
1857| [45667] Dovecot ACL plugin rights security bypass
1858
1859| [41085] Dovecot TAB characters authentication bypass
1860
1861| [41009] Dovecot mail_extra_groups option unauthorized access
1862
1863| [39342] Dovecot LDAP auth cache configuration security bypass
1864
1865| [35767] Dovecot ACL plugin security bypass
1866
1867| [34082] Dovecot mbox-storage.c directory traversal
1868
1869| [30433] Dovecot IMAP/POP3 server dovecot.index.cache buffer overflow
1870
1871| [26536] Dovecot IMAP LIST information disclosure
1872
1873| [24710] Dovecot dovecot-auth and imap/pop3-login denial of service
1874
1875| [24709] Dovecot APPEND command denial of service
1876
1877| [22629] RHSA-2005:408 updates for cyrus-imapd not installed
1878
1879| [19460] Cyrus IMAP imapd buffer overflow
1880
1881| [19455] Cyrus IMAP imapd extension off-by-one buffer overflow
1882
1883| [18492] Novell NetMail IMAPD 101_mEna buffer overflow
1884
1885| [10803] UW IMAP (wu-imapd) authenticated user buffer overflow
1886
1887| [9238] UW IMAP (wu-imapd) could allow a remote attacker to access arbitrary files
1888
1889| [9055] UW IMAP (wu-imapd) partial mailbox attributes to request buffer overflow
1890
1891| [7345] Slackware Linux imapd and ipop3d core dump
1892
1893| [573] Imapd denial of service
1894
1895|
1896
1897| Exploit-DB - http://www.exploit-db.com:
1898
1899| [1380] Eudora Qualcomm WorldMail 3.0 (IMAPd) Remote Overflow Exploit
1900
1901| [25297] Dovecot with Exim sender_address Parameter - Remote Command Execution
1902
1903| [22061] Cyrus IMAPD 1.4/1.5.19/2.0.12/2.0.16/2.1.9/2.1.10 Pre-Login Heap Corruption Vulnerability
1904
1905| [21443] Wu-imapd 2000/2001 Partial Mailbox Attribute Remote Buffer Overflow Vulnerability (2)
1906
1907| [21442] Wu-imapd 2000/2001 Partial Mailbox Attribute Remote Buffer Overflow Vulnerability (1)
1908
1909| [19849] UoW imapd 10.234/12.264 COPY Buffer Overflow (meta)
1910
1911| [19848] UoW imapd 10.234/12.264 LSUB Buffer Overflow (meta)
1912
1913| [19847] UoW imapd 10.234/12.264 Buffer Overflow Vulnerabilities
1914
1915| [19377] Ipswitch IMail 5.0 Imapd Buffer Overflow DoS Vulnerability
1916
1917| [19107] Netscape Messaging Server 3.55,University of Washington imapd 10.234 Buffer Overflow Vulnerability
1918
1919| [18354] WorldMail imapd 3.0 SEH overflow (egg hunter)
1920
1921| [16836] Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
1922
1923| [16485] MailEnable IMAPD (1.54) STATUS Request Buffer Overflow
1924
1925| [16482] MDaemon 9.6.4 IMAPD FETCH Buffer Overflow
1926
1927| [16480] MailEnable IMAPD W3C Logging Buffer Overflow
1928
1929| [16477] Mdaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow
1930
1931| [16475] MailEnable IMAPD (2.35) Login Request Buffer Overflow
1932
1933| [16474] Qualcomm WorldMail 3.0 IMAPD LIST Buffer Overflow
1934
1935| [5257] Dovecot IMAP 1.0.10 <= 1.1rc2 Remote Email Disclosure Exploit
1936
1937| [4429] Mercury/32 4.52 IMAPD SEARCH command Post-Auth Overflow Exploit
1938
1939| [3627] IPSwitch IMail Server <= 8.20 IMAPD Remote Buffer Overflow Exploit
1940
1941| [3527] Mercur IMAPD 5.00.14 Remote Denial of Service Exploit (win32)
1942
1943| [2185] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (3)
1944
1945| [2053] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (2)
1946
1947| [1813] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit
1948
1949| [1332] MailEnable 1.54 Pro Universal IMAPD W3C Logging BoF Exploit
1950
1951| [1327] FTGate4 Groupware Mail Server 4.1 (imapd) Remote Buffer Overflow PoC
1952
1953| [1151] MDaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow Exploit
1954
1955| [1124] IPSwitch IMail Server <= 8.15 IMAPD Remote Root Exploit
1956
1957| [915] MailEnable Enterprise 1.x Imapd Remote Exploit
1958
1959| [903] Cyrus imapd 2.2.4 - 2.2.8 (imapmagicplus) Remote Exploit
1960
1961| [340] Linux imapd Remote Overflow File Retrieve Exploit
1962
1963|
1964
1965| OpenVAS (Nessus) - http://www.openvas.org:
1966
1967| [901026] Dovecot Sieve Plugin Multiple Buffer Overflow Vulnerabilities
1968
1969| [901025] Dovecot Version Detection
1970
1971| [881425] CentOS Update for cyrus-imapd CESA-2011:1508 centos5 x86_64
1972
1973| [881403] CentOS Update for cyrus-imapd CESA-2011:0859 centos5 x86_64
1974
1975| [881402] CentOS Update for dovecot CESA-2011:1187 centos5 x86_64
1976
1977| [881397] CentOS Update for cyrus-imapd CESA-2011:1317 centos4 x86_64
1978
1979| [881370] CentOS Update for cyrus-imapd CESA-2011:1508 centos4 x86_64
1980
1981| [881358] CentOS Update for dovecot CESA-2011:1187 centos4 x86_64
1982
1983| [881318] CentOS Update for cyrus-imapd CESA-2011:0859 centos4 x86_64
1984
1985| [881255] CentOS Update for cyrus-imapd CESA-2011:1317 centos5 x86_64
1986
1987| [881050] CentOS Update for cyrus-imapd CESA-2011:1508 centos5 i386
1988
1989| [881049] CentOS Update for cyrus-imapd CESA-2011:1508 centos4 i386
1990
1991| [881007] CentOS Update for cyrus-imapd CESA-2011:1317 centos5 i386
1992
1993| [880980] CentOS Update for dovecot CESA-2011:1187 centos5 i386
1994
1995| [880978] CentOS Update for cyrus-imapd CESA-2011:1317 centos4 i386
1996
1997| [880967] CentOS Update for dovecot CESA-2011:1187 centos4 i386
1998
1999| [880958] CentOS Update for cyrus-imapd CESA-2011:0859 centos4 i386
2000
2001| [880905] CentOS Update for cyrus-imapd CESA-2009:1459 centos4 i386
2002
2003| [880864] CentOS Update for cyrus-imapd CESA-2009:1459 centos5 i386
2004
2005| [880826] CentOS Update for cyrus-imapd CESA-2009:1116 centos5 i386
2006
2007| [880536] CentOS Update for cyrus-imapd CESA-2011:0859 centos5 i386
2008
2009| [870607] RedHat Update for dovecot RHSA-2011:0600-01
2010
2011| [870520] RedHat Update for cyrus-imapd RHSA-2011:1508-01
2012
2013| [870489] RedHat Update for cyrus-imapd RHSA-2011:1317-01
2014
2015| [870471] RedHat Update for dovecot RHSA-2011:1187-01
2016
2017| [870443] RedHat Update for cyrus-imapd RHSA-2011:0859-01
2018
2019| [870153] RedHat Update for dovecot RHSA-2008:0297-02
2020
2021| [864075] Fedora Update for cyrus-imapd FEDORA-2011-13832
2022
2023| [863585] Fedora Update for cyrus-imapd FEDORA-2011-13869
2024
2025| [863579] Fedora Update for cyrus-imapd FEDORA-2011-13860
2026
2027| [863281] Fedora Update for cyrus-imapd FEDORA-2011-7193
2028
2029| [863273] Fedora Update for cyrus-imapd FEDORA-2011-7217
2030
2031| [863272] Fedora Update for dovecot FEDORA-2011-7612
2032
2033| [863115] Fedora Update for dovecot FEDORA-2011-7258
2034
2035| [861525] Fedora Update for dovecot FEDORA-2007-664
2036
2037| [861394] Fedora Update for dovecot FEDORA-2007-493
2038
2039| [861333] Fedora Update for dovecot FEDORA-2007-1485
2040
2041| [860845] Fedora Update for dovecot FEDORA-2008-9202
2042
2043| [860663] Fedora Update for dovecot FEDORA-2008-2475
2044
2045| [860169] Fedora Update for dovecot FEDORA-2008-2464
2046
2047| [860089] Fedora Update for dovecot FEDORA-2008-9232
2048
2049| [840950] Ubuntu Update for dovecot USN-1295-1
2050
2051| [840668] Ubuntu Update for dovecot USN-1143-1
2052
2053| [840583] Ubuntu Update for dovecot vulnerabilities USN-1059-1
2054
2055| [840335] Ubuntu Update for dovecot vulnerabilities USN-593-1
2056
2057| [840290] Ubuntu Update for dovecot vulnerability USN-567-1
2058
2059| [840234] Ubuntu Update for dovecot vulnerability USN-666-1
2060
2061| [840072] Ubuntu Update for dovecot vulnerability USN-487-1
2062
2063| [831590] Mandriva Update for cyrus-imapd MDVSA-2012:037 (cyrus-imapd)
2064
2065| [831468] Mandriva Update for cyrus-imapd MDVSA-2011:149 (cyrus-imapd)
2066
2067| [831410] Mandriva Update for cyrus-imapd MDVSA-2011:100 (cyrus-imapd)
2068
2069| [831405] Mandriva Update for dovecot MDVSA-2011:101 (dovecot)
2070
2071| [831230] Mandriva Update for dovecot MDVSA-2010:217 (dovecot)
2072
2073| [831207] Mandriva Update for cyrus-imapd MDVA-2010:208 (cyrus-imapd)
2074
2075| [831197] Mandriva Update for dovecot MDVSA-2010:196 (dovecot)
2076
2077| [831054] Mandriva Update for dovecot MDVSA-2010:104 (dovecot)
2078
2079| [830496] Mandriva Update for dovecot MDVSA-2008:232 (dovecot)
2080
2081| [801055] Dovecot 'base_dir' Insecure Permissions Security Bypass Vulnerability
2082
2083| [800149] UW-imapd tmail and dmail BOF Vulnerabilities (Linux)
2084
2085| [800030] Dovecot ACL Plugin Security Bypass Vulnerabilities
2086
2087| [70767] Gentoo Security Advisory GLSA 201110-04 (Dovecot)
2088
2089| [70696] Debian Security Advisory DSA 2377-1 (cyrus-imapd-2.2)
2090
2091| [70407] Debian Security Advisory DSA 2318-1 (cyrus-imapd-2.2)
2092
2093| [70259] FreeBSD Ports: dovecot
2094
2095| [69965] Debian Security Advisory DSA 2258-1 (kolab-cyrus-imapd)
2096
2097| [69959] Debian Security Advisory DSA 2252-1 (dovecot)
2098
2099| [69740] Debian Security Advisory DSA 2242-1 (cyrus-imapd-2.2)
2100
2101| [66522] FreeBSD Ports: dovecot
2102
2103| [66416] Mandriva Security Advisory MDVSA-2009:229-1 (cyrus-imapd)
2104
2105| [66233] SLES10: Security update for Cyrus IMAPD
2106
2107| [66226] SLES11: Security update for Cyrus IMAPD
2108
2109| [66222] SLES9: Security update for Cyrus IMAPD
2110
2111| [65938] SLES10: Security update for Cyrus IMAPD
2112
2113| [65723] SLES11: Security update for Cyrus IMAPD
2114
2115| [65523] SLES9: Security update for Cyrus IMAPD
2116
2117| [65479] SLES9: Security update for cyrus-imapd
2118
2119| [65094] SLES9: Security update for cyrus-imapd
2120
2121| [65010] Ubuntu USN-838-1 (dovecot)
2122
2123| [64989] CentOS Security Advisory CESA-2009:1459 (cyrus-imapd)
2124
2125| [64978] Debian Security Advisory DSA 1892-1 (dovecot)
2126
2127| [64977] Debian Security Advisory DSA 1893-1 (cyrus-imapd-2.2 kolab-cyrus-imapd)
2128
2129| [64965] Fedora Core 11 FEDORA-2009-9901 (cyrus-imapd)
2130
2131| [64963] Fedora Core 10 FEDORA-2009-9869 (cyrus-imapd)
2132
2133| [64953] Mandrake Security Advisory MDVSA-2009:242-1 (dovecot)
2134
2135| [64952] Mandrake Security Advisory MDVSA-2009:242 (dovecot)
2136
2137| [64898] FreeBSD Ports: cyrus-imapd
2138
2139| [64864] Debian Security Advisory DSA 1881-1 (cyrus-imapd-2.2)
2140
2141| [64861] Fedora Core 10 FEDORA-2009-9559 (dovecot)
2142
2143| [64847] Fedora Core 10 FEDORA-2009-9428 (cyrus-imapd)
2144
2145| [64846] Fedora Core 11 FEDORA-2009-9417 (cyrus-imapd)
2146
2147| [64838] Mandrake Security Advisory MDVSA-2009:229 (cyrus-imapd)
2148
2149| [64271] CentOS Security Advisory CESA-2009:1116 (cyrus-imapd)
2150
2151| [62965] Gentoo Security Advisory GLSA 200812-16 (dovecot)
2152
2153| [62854] FreeBSD Ports: dovecot-managesieve
2154
2155| [61916] FreeBSD Ports: dovecot
2156
2157| [60588] Gentoo Security Advisory GLSA 200803-25 (dovecot)
2158
2159| [60568] Debian Security Advisory DSA 1516-1 (dovecot)
2160
2161| [60528] FreeBSD Ports: dovecot
2162
2163| [60134] Debian Security Advisory DSA 1457-1 (dovecot)
2164
2165| [60089] FreeBSD Ports: dovecot
2166
2167| [58578] Debian Security Advisory DSA 1359-1 (dovecot)
2168
2169| [56834] Debian Security Advisory DSA 1080-1 (dovecot)
2170
2171| [55807] Slackware Advisory SSA:2005-310-06 imapd
2172
2173| [54861] Gentoo Security Advisory GLSA 200502-29 (cyrus-imapd)
2174
2175| [54755] Gentoo Security Advisory GLSA 200411-34 (cyrus-imapd)
2176
2177| [53739] Debian Security Advisory DSA 215-1 (cyrus-imapd)
2178
2179| [53288] Debian Security Advisory DSA 597-1 (cyrus-imapd)
2180
2181| [52297] FreeBSD Ports: cyrus-imapd
2182
2183| [52296] FreeBSD Ports: cyrus-imapd
2184
2185| [52295] FreeBSD Ports: cyrus-imapd
2186
2187| [52294] FreeBSD Ports: cyrus-imapd
2188
2189| [52172] FreeBSD Ports: cyrus-imapd
2190
2191|_
2192
2193179/tcp filtered bgp
2194
2195443/tcp open ssl/http Apache httpd 2.2.31 ((Unix) mod_ssl/2.2.31 OpenSSL/1.0.1e-fips mod_bwlimited/1.4)
2196
2197|_http-server-header: Apache/2.2.31 (Unix) mod_ssl/2.2.31 OpenSSL/1.0.1e-fips mod_bwlimited/1.4
2198
2199| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
2200
2201| [4527] Apache Struts up to 2.2.3.1 ExceptionDelegator Code Injection
2202
2203| [2452] Apache httpd up to 2.2.3 on Windows mod_alias Designfehler
2204
2205| [2414] Apache httpd up to 2.2.3 mod_rewrite buffer overflow
2206
2207| [9891] Apache HTTP Server 2.2.22 suEXEC Feature .htaccess information disclosure
2208
2209| [4583] Apache httpd up to 2.2.21 Threaded MPM denial of service
2210
2211| [4582] Apache httpd up to 2.2.21 protocol.c information disclosure
2212
2213| [4352] Apache httpd 2.2.x APR apr_fnmatch() denial of service
2214
2215| [2393] Apache httpd up to 2.2.2 HTTP Header Handler Expect-Header cross site scripting
2216
2217|
2218
2219| MITRE CVE - http://cve.mitre.org:
2220
2221| [CVE-2012-1006] Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
2222
2223| [CVE-2012-0838] Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
2224
2225| [CVE-2012-0391] The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
2226
2227| [CVE-2011-2087] Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
2228
2229| [CVE-2011-1772] Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
2230
2231| [CVE-2007-1743] suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root." In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.
2232
2233| [CVE-2007-1742] suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
2234
2235| [CVE-2007-1741] Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."
2236
2237| [CVE-2013-1896] mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
2238
2239| [CVE-2013-1862] mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
2240
2241| [CVE-2013-1768] The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
2242
2243| [CVE-2013-1048] The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
2244
2245| [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
2246
2247| [CVE-2012-4557] The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
2248
2249| [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
2250
2251| [CVE-2012-0216] The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
2252
2253| [CVE-2012-0053] protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
2254
2255| [CVE-2012-0031] scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
2256
2257| [CVE-2012-0021] The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.
2258
2259| [CVE-2011-5034] Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
2260
2261| [CVE-2011-4668] IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program used with the Apache HTTP Server.
2262
2263| [CVE-2011-4415] The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.
2264
2265| [CVE-2011-4317] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
2266
2267| [CVE-2011-3639] The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
2268
2269| [CVE-2011-3607] Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.
2270
2271| [CVE-2011-3368] The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
2272
2273| [CVE-2011-3348] The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
2274
2275| [CVE-2011-3192] The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
2276
2277| [CVE-2011-2088] XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
2278
2279| [CVE-2011-1928] The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.
2280
2281| [CVE-2011-1176] The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
2282
2283| [CVE-2011-0419] Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
2284
2285| [CVE-2010-4476] The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
2286
2287| [CVE-2010-2791] mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
2288
2289| [CVE-2010-2076] Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
2290
2291| [CVE-2010-2068] mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.
2292
2293| [CVE-2010-1452] The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
2294
2295| [CVE-2010-0434] The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
2296
2297| [CVE-2010-0425] modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
2298
2299| [CVE-2010-0408] The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
2300
2301| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
2302
2303| [CVE-2009-3094] The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
2304
2305| [CVE-2009-2699] The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
2306
2307| [CVE-2009-1891] The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
2308
2309| [CVE-2009-1195] The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
2310
2311| [CVE-2009-1191] mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
2312
2313| [CVE-2008-3666] Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured
2314
2315| [CVE-2008-2939] Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
2316
2317| [CVE-2008-2364] The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
2318
2319| [CVE-2008-2168] Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
2320
2321| [CVE-2008-0456] CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
2322
2323| [CVE-2008-0455] Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
2324
2325| [CVE-2008-0005] mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
2326
2327| [CVE-2007-6750] The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
2328
2329| [CVE-2007-6423] ** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
2330
2331| [CVE-2007-6422] The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
2332
2333| [CVE-2007-6421] Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
2334
2335| [CVE-2007-6420] Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
2336
2337| [CVE-2007-6388] Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2338
2339| [CVE-2007-6203] Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
2340
2341| [CVE-2007-5000] Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2342
2343| [CVE-2007-4465] Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
2344
2345| [CVE-2007-3304] Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
2346
2347| [CVE-2007-3303] Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.
2348
2349| [CVE-2007-1862] The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.
2350
2351| [CVE-2007-0792] The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
2352
2353| [CVE-2006-4110] Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
2354
2355| [CVE-2006-3918] http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
2356
2357| [CVE-2006-3747] Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
2358
2359| [CVE-2006-2806] The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.
2360
2361| [CVE-2006-1292] Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.
2362
2363| [CVE-2006-1079] htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
2364
2365| [CVE-2006-1078] Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
2366
2367| [CVE-2004-2650] Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
2368
2369| [CVE-2003-1172] Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
2370
2371| [CVE-2002-1233] A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
2372
2373|
2374
2375| OSVDB - http://www.osvdb.org:
2376
2377| [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
2378
2379|
2380
2381| SecurityFocus - http://www.securityfocus.com/bid/:
2382
2383| [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
2384
2385| [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
2386
2387|
2388
2389| SecurityTracker - http://www.securitytracker.com:
2390
2391| [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
2392
2393| [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
2394
2395| [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
2396
2397| [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
2398
2399| [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
2400
2401|
2402
2403| IBM X-Force - http://xforce.iss.net:
2404
2405| [75211] Debian GNU/Linux apache 2 cross-site scripting
2406
2407|
2408
2409| Exploit-DB - http://www.exploit-db.com:
2410
2411| [18329] Apache Struts2 <= 2.3.1 Multiple Vulnerabilities
2412
2413|
2414
2415| OpenVAS (Nessus) - http://www.openvas.org:
2416
2417| [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
2418
2419|_
2420
2421444/tcp filtered snpp
2422
2423465/tcp open ssl/smtp Exim smtpd 4.87
2424
2425| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
2426
2427| [6817] Exim up to 4.80 src/dkim.c dkim_exim_query_dns_txt() buffer overflow
2428
2429| [4280] Exim Server 4.x open_log() race condition
2430
2431| [1094] Exim Internet Mailer up to 4.43 SPA Authentication spa_base64_to_bits() buffer overflow
2432
2433| [1093] Exim Internet Mailer up to 4.43 IPv6 Address Handler host_aton() long IPv6 Address Designfehler
2434
2435| [647] Exim Internet Mailer up to 4.32 Header Handler header_syntax buffer overflow
2436
2437|
2438
2439| MITRE CVE - http://cve.mitre.org:
2440
2441| [CVE-2012-5671] Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.
2442
2443| [CVE-2012-0478] The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.
2444
2445| [CVE-2011-1764] Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.
2446
2447| [CVE-2011-1407] The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.
2448
2449| [CVE-2011-0017] The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
2450
2451| [CVE-2010-4345] Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
2452
2453| [CVE-2010-4344] Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
2454
2455| [CVE-2010-2024] transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.
2456
2457| [CVE-2010-2023] transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.
2458
2459| [CVE-2006-1251] Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
2460
2461| [CVE-2005-0022] Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.
2462
2463| [CVE-2005-0021] Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.
2464
2465| [CVE-2004-0400] Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.
2466
2467| [CVE-2004-0399] Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.
2468
2469| [CVE-2003-0743] Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.
2470
2471| [CVE-2002-1381] Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
2472
2473|
2474
2475| OSVDB - http://www.osvdb.org:
2476
2477| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
2478
2479| [87599] Mozilla Multiple Product copyTexImage2D Call Image Dimension Handling Memory Corruption
2480
2481| [87581] Mozilla Multiple Product texImage2D Call Handling Memory Corruption
2482
2483| [86616] Exim src/dkim.c dkim_exim_query_dns_txt() Function DNS Record Parsing Remote Overflow
2484
2485| [81523] Mozilla Multiple Product WebGL texImage2D() Function JSVAL_TO_OBJECT Remote Code Execution
2486
2487| [72642] Exim DKIM Identity Lookup Item Remote Code Execution
2488
2489| [72156] Exim src/dkim.c dkim_exim_verify_finish() Function DKIM-Signature Header Format String
2490
2491| [70696] Exim log.c open_log() Function Local Privilege Escalation
2492
2493| [69860] Exim exim User Account Configuration File Directive Local Privilege Escalation
2494
2495| [69685] Exim string_format Function Remote Overflow
2496
2497| [65159] Exim transports/appendfile.c MBX Locking Race Condition Permission Modification
2498
2499| [65158] Exim transports/appendfile.c Hardlink Handling Arbitrary File Overwrite
2500
2501| [57575] teximg Plugin for ikiwiki TEX Command Arbitrary File Local Disclosure
2502
2503| [23849] sa-exim greylistclean.cron Arbitrary File Deletion
2504
2505| [13073] Oracle Database Server Advanced Queuing Component dbms_transform_eximp Unspecified Security Issue
2506
2507| [12946] Exim -bh Command Line Option dns_build_reverse Function Local Overflow
2508
2509| [12727] Exim SPA Authentication spa_base64_to_bits Function Remote Overflow
2510
2511| [12726] Exim -be Command Line Option host_aton Function Local Overflow
2512
2513| [10877] Exim smtp_in.c HELO/EHLO Remote Overflow
2514
2515| [10360] Exim daemon.c pid_file_path Variable Manipulation Arbitrary Command Execution
2516
2517| [10032] libXpm CreateXImage Function Integer Overflow
2518
2519| [7160] Exim .forward :include: Option Privilege Escalation
2520
2521| [6479] Vexim COOKIE Authentication Credential Disclosure
2522
2523| [6478] Vexim Multiple Parameter SQL Injection
2524
2525| [5930] Exim Parenthesis File Name Filter Bypass
2526
2527| [5897] Exim header_syntax Function Remote Overflow
2528
2529| [5896] Exim sender_verify Function Remote Overflow
2530
2531| [5530] Exim Localhost Name Arbitrary Command Execution
2532
2533| [5330] Exim Configuration File Variable Overflow
2534
2535| [1855] Exim Batched SMTP Mail Header Format String
2536
2537|
2538
2539| SecurityFocus - http://www.securityfocus.com/bid/:
2540
2541| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
2542
2543| [56285] Exim DKIM DNS Decoding CVE-2012-5671 Remote Buffer Overflow Vulnerability
2544
2545| [47836] Exim DKIM CVE-2011-1407 Remote Code Execution Vulnerability
2546
2547| [47736] Exim 'dkim_exim_verify_finish()' Remote Format String Vulnerability
2548
2549| [46065] Exim 'log.c' Local Privilege Escalation Vulnerability
2550
2551| [45341] Exim ALT_CONFIG_ROOT_ONLY 'exim' User Local Privilege Escalation Vulnerability
2552
2553| [45308] Exim Crafted Header Remote Code Execution Vulnerability
2554
2555| [40454] Exim MBX Locking Insecure Temporary File Creation Vulnerability
2556
2557| [40451] Exim Sticky Mail Directory Local Privilege Escalation Vulnerability
2558
2559| [36181] ikiwiki 'teximg' Plugin Insecure TeX Commands Information Disclosure Vulnerability
2560
2561| [23977] Exim SpamAssassin Reply Remote Buffer Overflow Vulnerability
2562
2563| [17110] sa-exim Unauthorized File Access Vulnerability
2564
2565| [12268] Exim IP Address Command Line Argument Local Buffer Overflow Vulnerability
2566
2567| [12188] Exim SPA Authentication Remote Buffer Overflow Vulnerability
2568
2569| [12185] Exim Illegal IPv6 Address Buffer Overflow Vulnerability
2570
2571| [10291] Exim Header Syntax Checking Remote Stack Buffer Overrun Vulnerability
2572
2573| [10290] Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
2574
2575| [8518] Exim EHLO/HELO Remote Heap Corruption Vulnerability
2576
2577| [6314] Exim Internet Mailer Format String Vulnerability
2578
2579| [4096] Exim Configuration File Argument Command Line Buffer Overflow Vulnerability
2580
2581| [3728] Exim Pipe Hostname Arbitrary Command Execution Vulnerability
2582
2583| [2828] Exim Format String Vulnerability
2584
2585| [1859] Exim Buffer Overflow Vulnerability
2586
2587|
2588
2589| SecurityTracker - http://www.securitytracker.com:
2590
2591| [1025539] Exim DKIM Processing Flaw Lets Remote Users Execute Arbitrary Code
2592
2593| [1025504] Exim DKIM Signature Format String Flaw Lets Remote Users Execute Arbitrary Code
2594
2595| [1024859] Exim Configuration File Capability Lets Local Users Gain Elevated Privileges
2596
2597| [1024858] Exim Buffer Overfow in string_format() Lets Remote Users Execute Arbitrary Code
2598
2599| [1012904] Exim Buffer Overflow in dns_build_reverse() Lets Local Users Obtain Elevated Privileges
2600
2601| [1012771] Exim Buffer Overflows in host_aton() and spa_base64_to_bits() May Let Local Users Gain Elevated Privileges
2602
2603| [1010081] Exim Buffer Overflows in 'accept.c' and 'verify.c' Let Remote Users Execute Arbitrary Code
2604
2605| [1007609] Exim Heap Overflow in 'smtp_in.c' May Allow Remote Arbitrary Code Execution
2606
2607| [1005756] Exim Mail Server Format String Bug Lets Local Exim Administrators Execute Arbitrary Code With Root Privileges
2608
2609| [1003547] Potential Bug in Exim Mail Server May Let Local Users Execute Code With Root Privileges
2610
2611| [1003014] Exim Mail Server Pipe Address Validation Error May Let Remote Users Execute Arbitrary Code With Root Privileges in a Certain Configuration
2612
2613| [1001694] Exim Mail Server May Allow Remote Users to Execute Arbitrary Code with Root-Level Privileges on the Server
2614
2615|
2616
2617| IBM X-Force - http://xforce.iss.net:
2618
2619| [84758] Exim sender_address parameter command execution
2620
2621| [84015] Exim command execution
2622
2623| [80186] Mozilla Firefox, Thunderbird, and SeaMonkey copyTexImage2D code execution
2624
2625| [80184] Mozilla Firefox, Thunderbird, and SeaMonkey texImage2D calls code execution
2626
2627| [79615] Exim dkim_exim_query_dns_txt() buffer overflow
2628
2629| [75155] Mozilla Firefox, Thunderbird, and SeaMonkey texImage2D denial of service
2630
2631| [67455] Exim DKIM processing code execution
2632
2633| [67299] Exim dkim_exim_verify_finish() format string
2634
2635| [65028] Exim open_log privilege escalation
2636
2637| [63967] Exim config file privilege escalation
2638
2639| [63960] Exim header buffer overflow
2640
2641| [59043] Exim mail directory privilege escalation
2642
2643| [59042] Exim MBX symlink
2644
2645| [52922] ikiwiki teximg plugin information disclosure
2646
2647| [34265] Exim spamd buffer overflow
2648
2649| [25286] Sa-exim greylistclean.cron file deletion
2650
2651| [22687] RHSA-2005:025 updates for exim not installed
2652
2653| [18901] Exim dns_build_reverse buffer overflow
2654
2655| [18764] Exim spa_base64_to_bits function buffer overflow
2656
2657| [18763] Exim host_aton buffer overflow
2658
2659| [16079] Exim require_verify buffer overflow
2660
2661| [16077] Exim header_check_syntax buffer overflow
2662
2663| [16075] Exim sender_verify buffer overflow
2664
2665| [13067] Exim HELO or EHLO command heap overflow
2666
2667| [10761] Exim daemon.c format string
2668
2669| [8194] Exim configuration file -c command-line argument buffer overflow
2670
2671| [7738] Exim allows attacker to hide commands in localhost names using pipes
2672
2673| [6671] Exim "
2674
2675| [1893] Exim MTA allows local users to gain root privileges
2676
2677|
2678
2679| Exploit-DB - http://www.exploit-db.com:
2680
2681| [16925] Exim4 <= 4.69 string_format Function Heap Buffer Overflow
2682
2683|
2684
2685| OpenVAS (Nessus) - http://www.openvas.org:
2686
2687| [100663] Exim < 4.72 RC2 Multiple Vulnerabilities
2688
2689|_
2690
2691513/tcp filtered login
2692
2693587/tcp open smtp Exim smtpd 4.87
2694
2695| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
2696
2697| [6817] Exim up to 4.80 src/dkim.c dkim_exim_query_dns_txt() buffer overflow
2698
2699| [4280] Exim Server 4.x open_log() race condition
2700
2701| [1094] Exim Internet Mailer up to 4.43 SPA Authentication spa_base64_to_bits() buffer overflow
2702
2703| [1093] Exim Internet Mailer up to 4.43 IPv6 Address Handler host_aton() long IPv6 Address Designfehler
2704
2705| [647] Exim Internet Mailer up to 4.32 Header Handler header_syntax buffer overflow
2706
2707|
2708
2709| MITRE CVE - http://cve.mitre.org:
2710
2711| [CVE-2012-5671] Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.
2712
2713| [CVE-2012-0478] The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.
2714
2715| [CVE-2011-1764] Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.
2716
2717| [CVE-2011-1407] The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.
2718
2719| [CVE-2011-0017] The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
2720
2721| [CVE-2010-4345] Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
2722
2723| [CVE-2010-4344] Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
2724
2725| [CVE-2010-2024] transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.
2726
2727| [CVE-2010-2023] transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.
2728
2729| [CVE-2006-1251] Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
2730
2731| [CVE-2005-0022] Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.
2732
2733| [CVE-2005-0021] Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.
2734
2735| [CVE-2004-0400] Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.
2736
2737| [CVE-2004-0399] Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.
2738
2739| [CVE-2003-0743] Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.
2740
2741| [CVE-2002-1381] Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
2742
2743|
2744
2745| OSVDB - http://www.osvdb.org:
2746
2747| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
2748
2749| [87599] Mozilla Multiple Product copyTexImage2D Call Image Dimension Handling Memory Corruption
2750
2751| [87581] Mozilla Multiple Product texImage2D Call Handling Memory Corruption
2752
2753| [86616] Exim src/dkim.c dkim_exim_query_dns_txt() Function DNS Record Parsing Remote Overflow
2754
2755| [81523] Mozilla Multiple Product WebGL texImage2D() Function JSVAL_TO_OBJECT Remote Code Execution
2756
2757| [72642] Exim DKIM Identity Lookup Item Remote Code Execution
2758
2759| [72156] Exim src/dkim.c dkim_exim_verify_finish() Function DKIM-Signature Header Format String
2760
2761| [70696] Exim log.c open_log() Function Local Privilege Escalation
2762
2763| [69860] Exim exim User Account Configuration File Directive Local Privilege Escalation
2764
2765| [69685] Exim string_format Function Remote Overflow
2766
2767| [65159] Exim transports/appendfile.c MBX Locking Race Condition Permission Modification
2768
2769| [65158] Exim transports/appendfile.c Hardlink Handling Arbitrary File Overwrite
2770
2771| [57575] teximg Plugin for ikiwiki TEX Command Arbitrary File Local Disclosure
2772
2773| [23849] sa-exim greylistclean.cron Arbitrary File Deletion
2774
2775| [13073] Oracle Database Server Advanced Queuing Component dbms_transform_eximp Unspecified Security Issue
2776
2777| [12946] Exim -bh Command Line Option dns_build_reverse Function Local Overflow
2778
2779| [12727] Exim SPA Authentication spa_base64_to_bits Function Remote Overflow
2780
2781| [12726] Exim -be Command Line Option host_aton Function Local Overflow
2782
2783| [10877] Exim smtp_in.c HELO/EHLO Remote Overflow
2784
2785| [10360] Exim daemon.c pid_file_path Variable Manipulation Arbitrary Command Execution
2786
2787| [10032] libXpm CreateXImage Function Integer Overflow
2788
2789| [7160] Exim .forward :include: Option Privilege Escalation
2790
2791| [6479] Vexim COOKIE Authentication Credential Disclosure
2792
2793| [6478] Vexim Multiple Parameter SQL Injection
2794
2795| [5930] Exim Parenthesis File Name Filter Bypass
2796
2797| [5897] Exim header_syntax Function Remote Overflow
2798
2799| [5896] Exim sender_verify Function Remote Overflow
2800
2801| [5530] Exim Localhost Name Arbitrary Command Execution
2802
2803| [5330] Exim Configuration File Variable Overflow
2804
2805| [1855] Exim Batched SMTP Mail Header Format String
2806
2807|
2808
2809| SecurityFocus - http://www.securityfocus.com/bid/:
2810
2811| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
2812
2813| [56285] Exim DKIM DNS Decoding CVE-2012-5671 Remote Buffer Overflow Vulnerability
2814
2815| [47836] Exim DKIM CVE-2011-1407 Remote Code Execution Vulnerability
2816
2817| [47736] Exim 'dkim_exim_verify_finish()' Remote Format String Vulnerability
2818
2819| [46065] Exim 'log.c' Local Privilege Escalation Vulnerability
2820
2821| [45341] Exim ALT_CONFIG_ROOT_ONLY 'exim' User Local Privilege Escalation Vulnerability
2822
2823| [45308] Exim Crafted Header Remote Code Execution Vulnerability
2824
2825| [40454] Exim MBX Locking Insecure Temporary File Creation Vulnerability
2826
2827| [40451] Exim Sticky Mail Directory Local Privilege Escalation Vulnerability
2828
2829| [36181] ikiwiki 'teximg' Plugin Insecure TeX Commands Information Disclosure Vulnerability
2830
2831| [23977] Exim SpamAssassin Reply Remote Buffer Overflow Vulnerability
2832
2833| [17110] sa-exim Unauthorized File Access Vulnerability
2834
2835| [12268] Exim IP Address Command Line Argument Local Buffer Overflow Vulnerability
2836
2837| [12188] Exim SPA Authentication Remote Buffer Overflow Vulnerability
2838
2839| [12185] Exim Illegal IPv6 Address Buffer Overflow Vulnerability
2840
2841| [10291] Exim Header Syntax Checking Remote Stack Buffer Overrun Vulnerability
2842
2843| [10290] Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
2844
2845| [8518] Exim EHLO/HELO Remote Heap Corruption Vulnerability
2846
2847| [6314] Exim Internet Mailer Format String Vulnerability
2848
2849| [4096] Exim Configuration File Argument Command Line Buffer Overflow Vulnerability
2850
2851| [3728] Exim Pipe Hostname Arbitrary Command Execution Vulnerability
2852
2853| [2828] Exim Format String Vulnerability
2854
2855| [1859] Exim Buffer Overflow Vulnerability
2856
2857|
2858
2859| SecurityTracker - http://www.securitytracker.com:
2860
2861| [1025539] Exim DKIM Processing Flaw Lets Remote Users Execute Arbitrary Code
2862
2863| [1025504] Exim DKIM Signature Format String Flaw Lets Remote Users Execute Arbitrary Code
2864
2865| [1024859] Exim Configuration File Capability Lets Local Users Gain Elevated Privileges
2866
2867| [1024858] Exim Buffer Overfow in string_format() Lets Remote Users Execute Arbitrary Code
2868
2869| [1012904] Exim Buffer Overflow in dns_build_reverse() Lets Local Users Obtain Elevated Privileges
2870
2871| [1012771] Exim Buffer Overflows in host_aton() and spa_base64_to_bits() May Let Local Users Gain Elevated Privileges
2872
2873| [1010081] Exim Buffer Overflows in 'accept.c' and 'verify.c' Let Remote Users Execute Arbitrary Code
2874
2875| [1007609] Exim Heap Overflow in 'smtp_in.c' May Allow Remote Arbitrary Code Execution
2876
2877| [1005756] Exim Mail Server Format String Bug Lets Local Exim Administrators Execute Arbitrary Code With Root Privileges
2878
2879| [1003547] Potential Bug in Exim Mail Server May Let Local Users Execute Code With Root Privileges
2880
2881| [1003014] Exim Mail Server Pipe Address Validation Error May Let Remote Users Execute Arbitrary Code With Root Privileges in a Certain Configuration
2882
2883| [1001694] Exim Mail Server May Allow Remote Users to Execute Arbitrary Code with Root-Level Privileges on the Server
2884
2885|
2886
2887| IBM X-Force - http://xforce.iss.net:
2888
2889| [84758] Exim sender_address parameter command execution
2890
2891| [84015] Exim command execution
2892
2893| [80186] Mozilla Firefox, Thunderbird, and SeaMonkey copyTexImage2D code execution
2894
2895| [80184] Mozilla Firefox, Thunderbird, and SeaMonkey texImage2D calls code execution
2896
2897| [79615] Exim dkim_exim_query_dns_txt() buffer overflow
2898
2899| [75155] Mozilla Firefox, Thunderbird, and SeaMonkey texImage2D denial of service
2900
2901| [67455] Exim DKIM processing code execution
2902
2903| [67299] Exim dkim_exim_verify_finish() format string
2904
2905| [65028] Exim open_log privilege escalation
2906
2907| [63967] Exim config file privilege escalation
2908
2909| [63960] Exim header buffer overflow
2910
2911| [59043] Exim mail directory privilege escalation
2912
2913| [59042] Exim MBX symlink
2914
2915| [52922] ikiwiki teximg plugin information disclosure
2916
2917| [34265] Exim spamd buffer overflow
2918
2919| [25286] Sa-exim greylistclean.cron file deletion
2920
2921| [22687] RHSA-2005:025 updates for exim not installed
2922
2923| [18901] Exim dns_build_reverse buffer overflow
2924
2925| [18764] Exim spa_base64_to_bits function buffer overflow
2926
2927| [18763] Exim host_aton buffer overflow
2928
2929| [16079] Exim require_verify buffer overflow
2930
2931| [16077] Exim header_check_syntax buffer overflow
2932
2933| [16075] Exim sender_verify buffer overflow
2934
2935| [13067] Exim HELO or EHLO command heap overflow
2936
2937| [10761] Exim daemon.c format string
2938
2939| [8194] Exim configuration file -c command-line argument buffer overflow
2940
2941| [7738] Exim allows attacker to hide commands in localhost names using pipes
2942
2943| [6671] Exim "
2944
2945| [1893] Exim MTA allows local users to gain root privileges
2946
2947|
2948
2949| Exploit-DB - http://www.exploit-db.com:
2950
2951| [16925] Exim4 <= 4.69 string_format Function Heap Buffer Overflow
2952
2953|
2954
2955| OpenVAS (Nessus) - http://www.openvas.org:
2956
2957| [100663] Exim < 4.72 RC2 Multiple Vulnerabilities
2958
2959|_
2960
2961593/tcp filtered http-rpc-epmap
2962
2963993/tcp open ssl/imap Dovecot imapd
2964
2965| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
2966
2967| [9807] Dovecot up to 1.2.7 on Exim Input Sanitizer MAIL FROM privilege escalation
2968
2969| [7062] Dovecot 2.1.10 lib-storage/mail-search.c denial of service
2970
2971|
2972
2973| MITRE CVE - http://cve.mitre.org:
2974
2975| [CVE-2009-2632] Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
2976
2977| [CVE-2011-4318] Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
2978
2979| [CVE-2011-3481] The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.
2980
2981| [CVE-2011-3372] imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
2982
2983| [CVE-2011-2167] script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
2984
2985| [CVE-2011-2166] script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
2986
2987| [CVE-2011-1929] lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
2988
2989| [CVE-2010-4011] Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
2990
2991| [CVE-2010-3780] Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
2992
2993| [CVE-2010-3779] Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
2994
2995| [CVE-2010-3707] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
2996
2997| [CVE-2010-3706] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
2998
2999| [CVE-2010-3304] The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
3000
3001| [CVE-2010-0745] Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.
3002
3003| [CVE-2010-0535] Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
3004
3005| [CVE-2010-0433] The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
3006
3007| [CVE-2009-3897] Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
3008
3009| [CVE-2009-3235] Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
3010
3011| [CVE-2008-5301] Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
3012
3013| [CVE-2008-4907] The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
3014
3015| [CVE-2008-4870] dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
3016
3017| [CVE-2008-4578] The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
3018
3019| [CVE-2008-4577] The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
3020
3021| [CVE-2008-1218] Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.
3022
3023| [CVE-2008-1199] Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
3024
3025| [CVE-2007-6598] Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
3026
3027| [CVE-2007-5794] Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
3028
3029| [CVE-2007-5740] The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.
3030
3031| [CVE-2007-5018] Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.
3032
3033| [CVE-2007-4211] The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
3034
3035| [CVE-2007-3925] Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.
3036
3037| [CVE-2007-2231] Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
3038
3039| [CVE-2007-2173] Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
3040
3041| [CVE-2007-1579] Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command.
3042
3043| [CVE-2007-1578] Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.
3044
3045| [CVE-2007-0618] Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
3046
3047| [CVE-2006-6762] The IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to cause a denial of service via an APPEND command with a single "(" (parenthesis) in the argument.
3048
3049| [CVE-2006-6761] Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via a long argument to the SUBSCRIBE command.
3050
3051| [CVE-2006-6425] Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via unspecified vectors involving the APPEND command.
3052
3053| [CVE-2006-6424] Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow
3054
3055| [CVE-2006-5973] Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
3056
3057| [CVE-2006-2502] Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
3058
3059| [CVE-2006-2414] Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
3060
3061| [CVE-2006-0730] Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
3062
3063| [CVE-2005-2278] Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.
3064
3065| [CVE-2005-1256] Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.
3066
3067| [CVE-2005-1249] The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop.
3068
3069| [CVE-2005-1015] Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
3070
3071| [CVE-2005-0546] Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapd annotate extension, (2) an off-by-one error in "cached header handling," (3) a stack-based buffer overflow in fetchnews, or (4) a stack-based buffer overflow in imapd.
3072
3073| [CVE-2003-1322] Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10) CREATE, or (11) SELECT command.
3074
3075| [CVE-2002-1782] The default configuration of University of Washington IMAP daemon (wu-imapd), when running on a system that does not allow shell access, allows a local user with a valid IMAP account to read arbitrary files as that user.
3076
3077| [CVE-2002-1604] Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver.
3078
3079| [CVE-2002-0997] Buffer overflows in IMAP Agent (imapd) for Novell NetMail (NIMS) 3.0.3 before 3.0.3A allows remote attackers to cause a denial of service.
3080
3081| [CVE-2002-0379] Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and earlier, allows remote authenticated users to execute arbitrary code via a long BODY request.
3082
3083| [CVE-2001-0691] Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.
3084
3085| [CVE-2000-0284] Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.
3086
3087| [CVE-1999-1557] Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.
3088
3089| [CVE-1999-1445] Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.
3090
3091| [CVE-1999-1224] IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information.
3092
3093|
3094
3095| OSVDB - http://www.osvdb.org:
3096
3097| [96172] Dovecot POP3 Service Terminated LIST Command Remote DoS
3098
3099| [93525] Dovecot IMAP APPEND Command Malformed Parameter Parsing Remote DoS
3100
3101| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
3102
3103| [88058] Dovecot lib-storage/mail-search.c Multiple Keyword Search Handling Remote DoS
3104
3105| [78304] Eudora WorldMail imapd SEH LIST Command Parsing Remote Overflow
3106
3107| [77185] Dovecot SSL Certificate Common Name Field MitM Spoofing Weakness
3108
3109| [75445] Cyrus IMAP Server imapd index.c index_get_ids Function References Header NULL Dereference Remote DoS
3110
3111| [74515] Dovecot script-login chroot Configuration Setting Traversal Arbitrary File Access
3112
3113| [74514] Dovecot script-login User / Group Configuration Settings Remote Access Restriction Bypass
3114
3115| [72495] Dovecot lib-mail/message-header-parser.c Mail Header Name NULL Character Handling Remote DoS
3116
3117| [69260] Apple Mac OS X Server Dovecot Memory Aliasing Mail Delivery Issue
3118
3119| [68516] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition User Private Namespace Mailbox Access Restriction Remote Bypass
3120
3121| [68515] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition Specific Entry Order Mailbox Access Restriction Remote Bypass
3122
3123| [68513] Dovecot Non-public Namespace Mailbox ACL Manipulation Access Restriction Remote Bypass
3124
3125| [68512] Dovecot IMAP / POP3 Session Disconnect Master Process Outage Remote DoS
3126
3127| [66625] Dovecot ACL Plugin INBOX ACL Copying Weakness Restriction Bypass
3128
3129| [66113] Dovecot Mail Root Directory Creation Permission Weakness
3130
3131| [66112] Dovecot Installation base_dir Parent Directory Permission Weakness
3132
3133| [66111] Dovecot SEARCH Functionality str_find_init() Function Overflow
3134
3135| [66110] Dovecot Multiple Unspecified Buffer Overflows
3136
3137| [66108] Dovecot Malformed Message Body Processing Unspecified Functions Remote DoS
3138
3139| [64783] Dovecot E-mail Message Header Unspecified DoS
3140
3141| [63372] Apple Mac OS X Dovecot Kerberos Authentication SACL Restriction Bypass
3142
3143| [62796] Dovecot mbox Format Email Header Handling DoS
3144
3145| [60316] Dovecot base_dir Directory Permission Weakness Local Privilege Escalation
3146
3147| [58103] Dovecot CMU Sieve Plugin Script Handling Multiple Overflows
3148
3149| [57843] Cyrus IMAP Server (cyrus-imapd) SIEVE Script Component (sieve/script.c) Crafted Script Handling Overflow
3150
3151| [57681] UoW imap Server (uw-imapd) Arbitrary Remote File Access
3152
3153| [52906] UW-imapd c-client Initial Request Remote Format String
3154
3155| [52905] UW-imapd c-client Library RFC822BUFFER Routines rfc822_output_char Function Off-by-one
3156
3157| [52456] UW-imapd on Debian Linux LOGIN Command Remote DoS
3158
3159| [50253] Dovecot dovecot.conf Permission Weakness Local ssl_key_password Parameter Disclosure
3160
3161| [49918] Dovecot ManageSieve Script Name Handling Traversal Arbitrary File Manipulation
3162
3163| [49485] UW-imapd dmail Utility Mailbox Name Handling Overflow
3164
3165| [49484] UW-imapd tmail Utility Mailbox Name Handling Overflow
3166
3167| [49429] Dovecot Message Parsing Feature Crafted Email Header Handling Remote DoS
3168
3169| [49099] Dovecot ACL Plugin k Right Mailbox Creation Restriction Bypass
3170
3171| [49098] Dovecot ACL Plugin Negative Access Rights Bypass
3172
3173| [43137] Dovecot mail_extra_groups Symlink File Manipulation
3174
3175| [42979] Dovecot passdbs Argument Injection Authentication Bypass
3176
3177| [42004] Perdition Mail Retrieval Proxy IMAPD IMAP Tag Remote Format String Arbitrary Code Execution
3178
3179| [39876] Dovecot LDAP Auth Cache Security Bypass
3180
3181| [39670] Mercury Mail Transport System IMAPD SEARCH Command Remote Overflow
3182
3183| [39386] Dovecot ACL Plugin Insert Right APPEND / COPY Command Unauthorized Flag Manipulation
3184
3185| [35489] Dovecot index/mbox/mbox-storage.c Traversal Arbitrary Gzip File Access
3186
3187| [31362] Novell NetMail IMAP Daemon (IMAPD) APPEND Command Remote Overflow
3188
3189| [31361] Novell NetMail IMAP Daemon (IMAPD) APPEND Command DoS
3190
3191| [31360] Novell NetMail IMAP Daemon (IMAPD) SUBSCRIBE Command Remote Overflow
3192
3193| [30524] Dovecot IMAP/POP3 Server dovecot.index.cache Handling Overflow
3194
3195| [25853] Cyrus IMAPD pop3d USER Command Remote Overflow
3196
3197| [25727] Dovecot Multiple Command Traversal Arbitrary Directory Listing
3198
3199| [23281] Dovecot imap/pop3-login dovecot-auth DoS
3200
3201| [23280] Dovecot Malformed APPEND Command DoS
3202
3203| [18179] HP Tru64 UNIX imapd NLSPATH Environment Variable Local Overflow
3204
3205| [13242] UW-imapd CRAM-MD5 Authentication Bypass
3206
3207| [12385] Novell NetMail IMAPD 101_mEna Script Remote Overflow
3208
3209| [12042] UoW imapd Multiple Unspecified Overflows
3210
3211| [12037] UoW imapd (UW-IMAP) Multiple Command Remote Overflows
3212
3213| [12033] Slackware Linux imapd/ipop3d Malformed USER/PASS Sequence DoS
3214
3215| [911] UoW imapd AUTHENTICATE Command Remote Overflow
3216
3217| [790] UoW imap Server (uw-imapd) BODY Request Remote Overflow
3218
3219| [519] UoW imapd SIGABRT Signal Forced Crash Information Disclosure
3220
3221|
3222
3223| SecurityFocus - http://www.securityfocus.com/bid/:
3224
3225| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
3226
3227| [60052] Dovecot 'APPEND' Parameter Denial of Service Vulnerability
3228
3229| [56759] RETIRED: Dovecot 'mail-search.c' Denial of Service Vulnerability
3230
3231| [51403] Eudora WorldMail imapd 'LIST' Command Buffer Overflow Vulnerability
3232
3233| [50709] Dovecot SSL Certificate 'Common Name' Field Validation Security Bypass Vulnerability
3234
3235| [49949] Cyrus IMAPd NTTP Logic Error Authentication Bypass Vulnerability
3236
3237| [48003] Dovecot 'script-login' Multiple Security Bypass Vulnerabilities
3238
3239| [47930] Dovecot Header Name NULL Character Denial of Service Vulnerability
3240
3241| [44874] Apple Mac OS X Dovecot (CVE-2010-4011) Memory Corruption Vulnerability
3242
3243| [43690] Dovecot Access Control List (ACL) Multiple Remote Vulnerabilities
3244
3245| [41964] Dovecot Access Control List (ACL) Plugin Security Bypass Weakness
3246
3247| [39258] Dovecot Service Control Access List Security Bypass Vulnerability
3248
3249| [37084] Dovecot Insecure 'base_dir' Permissions Local Privilege Escalation Vulnerability
3250
3251| [36377] Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
3252
3253| [32582] Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
3254
3255| [31997] Dovecot Invalid Message Address Parsing Denial of Service Vulnerability
3256
3257| [31587] Dovecot ACL Plugin Multiple Security Bypass Vulnerabilities
3258
3259| [28181] Dovecot 'Tab' Character Password Check Security Bypass Vulnerability
3260
3261| [28092] Dovecot 'mail_extra_groups' Insecure Settings Local Unauthorized Access Vulnerability
3262
3263| [27093] Dovecot Authentication Cache Security Bypass Vulnerability
3264
3265| [26270] Perdition IMAPD __STR_VWRITE Remote Format String Vulnerability
3266
3267| [25733] Mercury/32 IMAPD SEARCH Command Remote Stack Buffer Overflow Vulnerability
3268
3269| [25182] Dovecot ACL Plugin Security Bypass Vulnerability
3270
3271| [23552] Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
3272
3273| [23058] Atrium Mercur IMapD NTLM Buffer Overflow Vulnerability
3274
3275| [22262] IBM AIX Pop3D/Pop3DS/IMapD/IMapDS Authentication Bypass Vulnerability
3276
3277| [21183] Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
3278
3279| [18056] Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
3280
3281| [17961] Dovecot Remote Information Disclosure Vulnerability
3282
3283| [16672] Dovecot Double Free Denial of Service Vulnerability
3284
3285| [15980] Qualcomm WorldMail IMAPD Buffer Overflow Vulnerability
3286
3287| [15753] Ipswitch Collaboration Suite and IMail Server IMAPD LIST Command Denial Of Service Vulnerability
3288
3289| [12636] Cyrus IMAPD Multiple Remote Buffer Overflow Vulnerabilities
3290
3291| [11738] Cyrus IMAPD Multiple Remote Unspecified Vulnerabilities
3292
3293| [11729] Cyrus IMAPD Multiple Remote Vulnerabilities
3294
3295| [6298] Cyrus IMAPD Pre-Login Heap Corruption Vulnerability
3296
3297| [4713] Wu-imapd Partial Mailbox Attribute Remote Buffer Overflow Vulnerability
3298
3299| [2856] Imapd 'Local' Buffer Overflow Vulnerabilities
3300
3301| [1110] Univ. Of Washington imapd Buffer Overflow Vulnerabilities
3302
3303| [502] NT IMail Imapd Buffer Overflow DoS Vulnerability
3304
3305| [130] imapd Buffer Overflow Vulnerability
3306
3307|
3308
3309| SecurityTracker - http://www.securitytracker.com:
3310
3311| [1028585] Dovecot APPEND Parameter Processing Flaw Lets Remote Authenticated Users Deny Service
3312
3313| [1024740] Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User
3314
3315| [1017288] Dovecot POP3/IMAP Cache File Buffer Overflow May Let Remote Users Execute Arbitrary Code
3316
3317| [1013278] Cyrus IMAPd Buffer Overflows in Annotate Extension, Cached Header, and Fetchnews May Let Remote Users Execute Arbitrary Code
3318
3319|
3320
3321| IBM X-Force - http://xforce.iss.net:
3322
3323| [86382] Dovecot POP3 Service denial of service
3324
3325| [84396] Dovecot IMAP APPEND denial of service
3326
3327| [80453] Dovecot mail-search.c denial of service
3328
3329| [71354] Dovecot SSL Common Name (CN) weak security
3330
3331| [70325] Cyrus IMAPd NNTP security bypass
3332
3333| [67675] Dovecot script-login security bypass
3334
3335| [67674] Dovecot script-login directory traversal
3336
3337| [67589] Dovecot header name denial of service
3338
3339| [63267] Apple Mac OS X Dovecot information disclosure
3340
3341| [62340] Dovecot mailbox security bypass
3342
3343| [62339] Dovecot IMAP or POP3 denial of service
3344
3345| [62256] Dovecot mailbox security bypass
3346
3347| [62255] Dovecot ACL entry security bypass
3348
3349| [60639] Dovecot ACL plugin weak security
3350
3351| [57267] Apple Mac OS X Dovecot Kerberos security bypass
3352
3353| [56763] Dovecot header denial of service
3354
3355| [54363] Dovecot base_dir privilege escalation
3356
3357| [53248] CMU Sieve plugin for Dovecot unspecified buffer overflow
3358
3359| [47526] UW-imapd rfc822_output_char() denial of service
3360
3361| [46323] Dovecot dovecot.conf information disclosure
3362
3363| [46227] Dovecot message parsing denial of service
3364
3365| [45669] Dovecot ACL mailbox security bypass
3366
3367| [45667] Dovecot ACL plugin rights security bypass
3368
3369| [41085] Dovecot TAB characters authentication bypass
3370
3371| [41009] Dovecot mail_extra_groups option unauthorized access
3372
3373| [39342] Dovecot LDAP auth cache configuration security bypass
3374
3375| [35767] Dovecot ACL plugin security bypass
3376
3377| [34082] Dovecot mbox-storage.c directory traversal
3378
3379| [30433] Dovecot IMAP/POP3 server dovecot.index.cache buffer overflow
3380
3381| [26536] Dovecot IMAP LIST information disclosure
3382
3383| [24710] Dovecot dovecot-auth and imap/pop3-login denial of service
3384
3385| [24709] Dovecot APPEND command denial of service
3386
3387| [22629] RHSA-2005:408 updates for cyrus-imapd not installed
3388
3389| [19460] Cyrus IMAP imapd buffer overflow
3390
3391| [19455] Cyrus IMAP imapd extension off-by-one buffer overflow
3392
3393| [18492] Novell NetMail IMAPD 101_mEna buffer overflow
3394
3395| [10803] UW IMAP (wu-imapd) authenticated user buffer overflow
3396
3397| [9238] UW IMAP (wu-imapd) could allow a remote attacker to access arbitrary files
3398
3399| [9055] UW IMAP (wu-imapd) partial mailbox attributes to request buffer overflow
3400
3401| [7345] Slackware Linux imapd and ipop3d core dump
3402
3403| [573] Imapd denial of service
3404
3405|
3406
3407| Exploit-DB - http://www.exploit-db.com:
3408
3409| [1380] Eudora Qualcomm WorldMail 3.0 (IMAPd) Remote Overflow Exploit
3410
3411| [25297] Dovecot with Exim sender_address Parameter - Remote Command Execution
3412
3413| [22061] Cyrus IMAPD 1.4/1.5.19/2.0.12/2.0.16/2.1.9/2.1.10 Pre-Login Heap Corruption Vulnerability
3414
3415| [21443] Wu-imapd 2000/2001 Partial Mailbox Attribute Remote Buffer Overflow Vulnerability (2)
3416
3417| [21442] Wu-imapd 2000/2001 Partial Mailbox Attribute Remote Buffer Overflow Vulnerability (1)
3418
3419| [19849] UoW imapd 10.234/12.264 COPY Buffer Overflow (meta)
3420
3421| [19848] UoW imapd 10.234/12.264 LSUB Buffer Overflow (meta)
3422
3423| [19847] UoW imapd 10.234/12.264 Buffer Overflow Vulnerabilities
3424
3425| [19377] Ipswitch IMail 5.0 Imapd Buffer Overflow DoS Vulnerability
3426
3427| [19107] Netscape Messaging Server 3.55,University of Washington imapd 10.234 Buffer Overflow Vulnerability
3428
3429| [18354] WorldMail imapd 3.0 SEH overflow (egg hunter)
3430
3431| [16836] Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
3432
3433| [16485] MailEnable IMAPD (1.54) STATUS Request Buffer Overflow
3434
3435| [16482] MDaemon 9.6.4 IMAPD FETCH Buffer Overflow
3436
3437| [16480] MailEnable IMAPD W3C Logging Buffer Overflow
3438
3439| [16477] Mdaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow
3440
3441| [16475] MailEnable IMAPD (2.35) Login Request Buffer Overflow
3442
3443| [16474] Qualcomm WorldMail 3.0 IMAPD LIST Buffer Overflow
3444
3445| [5257] Dovecot IMAP 1.0.10 <= 1.1rc2 Remote Email Disclosure Exploit
3446
3447| [4429] Mercury/32 4.52 IMAPD SEARCH command Post-Auth Overflow Exploit
3448
3449| [3627] IPSwitch IMail Server <= 8.20 IMAPD Remote Buffer Overflow Exploit
3450
3451| [3527] Mercur IMAPD 5.00.14 Remote Denial of Service Exploit (win32)
3452
3453| [2185] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (3)
3454
3455| [2053] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (2)
3456
3457| [1813] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit
3458
3459| [1332] MailEnable 1.54 Pro Universal IMAPD W3C Logging BoF Exploit
3460
3461| [1327] FTGate4 Groupware Mail Server 4.1 (imapd) Remote Buffer Overflow PoC
3462
3463| [1151] MDaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow Exploit
3464
3465| [1124] IPSwitch IMail Server <= 8.15 IMAPD Remote Root Exploit
3466
3467| [915] MailEnable Enterprise 1.x Imapd Remote Exploit
3468
3469| [903] Cyrus imapd 2.2.4 - 2.2.8 (imapmagicplus) Remote Exploit
3470
3471| [340] Linux imapd Remote Overflow File Retrieve Exploit
3472
3473|
3474
3475| OpenVAS (Nessus) - http://www.openvas.org:
3476
3477| [901026] Dovecot Sieve Plugin Multiple Buffer Overflow Vulnerabilities
3478
3479| [901025] Dovecot Version Detection
3480
3481| [881425] CentOS Update for cyrus-imapd CESA-2011:1508 centos5 x86_64
3482
3483| [881403] CentOS Update for cyrus-imapd CESA-2011:0859 centos5 x86_64
3484
3485| [881402] CentOS Update for dovecot CESA-2011:1187 centos5 x86_64
3486
3487| [881397] CentOS Update for cyrus-imapd CESA-2011:1317 centos4 x86_64
3488
3489| [881370] CentOS Update for cyrus-imapd CESA-2011:1508 centos4 x86_64
3490
3491| [881358] CentOS Update for dovecot CESA-2011:1187 centos4 x86_64
3492
3493| [881318] CentOS Update for cyrus-imapd CESA-2011:0859 centos4 x86_64
3494
3495| [881255] CentOS Update for cyrus-imapd CESA-2011:1317 centos5 x86_64
3496
3497| [881050] CentOS Update for cyrus-imapd CESA-2011:1508 centos5 i386
3498
3499| [881049] CentOS Update for cyrus-imapd CESA-2011:1508 centos4 i386
3500
3501| [881007] CentOS Update for cyrus-imapd CESA-2011:1317 centos5 i386
3502
3503| [880980] CentOS Update for dovecot CESA-2011:1187 centos5 i386
3504
3505| [880978] CentOS Update for cyrus-imapd CESA-2011:1317 centos4 i386
3506
3507| [880967] CentOS Update for dovecot CESA-2011:1187 centos4 i386
3508
3509| [880958] CentOS Update for cyrus-imapd CESA-2011:0859 centos4 i386
3510
3511| [880905] CentOS Update for cyrus-imapd CESA-2009:1459 centos4 i386
3512
3513| [880864] CentOS Update for cyrus-imapd CESA-2009:1459 centos5 i386
3514
3515| [880826] CentOS Update for cyrus-imapd CESA-2009:1116 centos5 i386
3516
3517| [880536] CentOS Update for cyrus-imapd CESA-2011:0859 centos5 i386
3518
3519| [870607] RedHat Update for dovecot RHSA-2011:0600-01
3520
3521| [870520] RedHat Update for cyrus-imapd RHSA-2011:1508-01
3522
3523| [870489] RedHat Update for cyrus-imapd RHSA-2011:1317-01
3524
3525| [870471] RedHat Update for dovecot RHSA-2011:1187-01
3526
3527| [870443] RedHat Update for cyrus-imapd RHSA-2011:0859-01
3528
3529| [870153] RedHat Update for dovecot RHSA-2008:0297-02
3530
3531| [864075] Fedora Update for cyrus-imapd FEDORA-2011-13832
3532
3533| [863585] Fedora Update for cyrus-imapd FEDORA-2011-13869
3534
3535| [863579] Fedora Update for cyrus-imapd FEDORA-2011-13860
3536
3537| [863281] Fedora Update for cyrus-imapd FEDORA-2011-7193
3538
3539| [863273] Fedora Update for cyrus-imapd FEDORA-2011-7217
3540
3541| [863272] Fedora Update for dovecot FEDORA-2011-7612
3542
3543| [863115] Fedora Update for dovecot FEDORA-2011-7258
3544
3545| [861525] Fedora Update for dovecot FEDORA-2007-664
3546
3547| [861394] Fedora Update for dovecot FEDORA-2007-493
3548
3549| [861333] Fedora Update for dovecot FEDORA-2007-1485
3550
3551| [860845] Fedora Update for dovecot FEDORA-2008-9202
3552
3553| [860663] Fedora Update for dovecot FEDORA-2008-2475
3554
3555| [860169] Fedora Update for dovecot FEDORA-2008-2464
3556
3557| [860089] Fedora Update for dovecot FEDORA-2008-9232
3558
3559| [840950] Ubuntu Update for dovecot USN-1295-1
3560
3561| [840668] Ubuntu Update for dovecot USN-1143-1
3562
3563| [840583] Ubuntu Update for dovecot vulnerabilities USN-1059-1
3564
3565| [840335] Ubuntu Update for dovecot vulnerabilities USN-593-1
3566
3567| [840290] Ubuntu Update for dovecot vulnerability USN-567-1
3568
3569| [840234] Ubuntu Update for dovecot vulnerability USN-666-1
3570
3571| [840072] Ubuntu Update for dovecot vulnerability USN-487-1
3572
3573| [831590] Mandriva Update for cyrus-imapd MDVSA-2012:037 (cyrus-imapd)
3574
3575| [831468] Mandriva Update for cyrus-imapd MDVSA-2011:149 (cyrus-imapd)
3576
3577| [831410] Mandriva Update for cyrus-imapd MDVSA-2011:100 (cyrus-imapd)
3578
3579| [831405] Mandriva Update for dovecot MDVSA-2011:101 (dovecot)
3580
3581| [831230] Mandriva Update for dovecot MDVSA-2010:217 (dovecot)
3582
3583| [831207] Mandriva Update for cyrus-imapd MDVA-2010:208 (cyrus-imapd)
3584
3585| [831197] Mandriva Update for dovecot MDVSA-2010:196 (dovecot)
3586
3587| [831054] Mandriva Update for dovecot MDVSA-2010:104 (dovecot)
3588
3589| [830496] Mandriva Update for dovecot MDVSA-2008:232 (dovecot)
3590
3591| [801055] Dovecot 'base_dir' Insecure Permissions Security Bypass Vulnerability
3592
3593| [800149] UW-imapd tmail and dmail BOF Vulnerabilities (Linux)
3594
3595| [800030] Dovecot ACL Plugin Security Bypass Vulnerabilities
3596
3597| [70767] Gentoo Security Advisory GLSA 201110-04 (Dovecot)
3598
3599| [70696] Debian Security Advisory DSA 2377-1 (cyrus-imapd-2.2)
3600
3601| [70407] Debian Security Advisory DSA 2318-1 (cyrus-imapd-2.2)
3602
3603| [70259] FreeBSD Ports: dovecot
3604
3605| [69965] Debian Security Advisory DSA 2258-1 (kolab-cyrus-imapd)
3606
3607| [69959] Debian Security Advisory DSA 2252-1 (dovecot)
3608
3609| [69740] Debian Security Advisory DSA 2242-1 (cyrus-imapd-2.2)
3610
3611| [66522] FreeBSD Ports: dovecot
3612
3613| [66416] Mandriva Security Advisory MDVSA-2009:229-1 (cyrus-imapd)
3614
3615| [66233] SLES10: Security update for Cyrus IMAPD
3616
3617| [66226] SLES11: Security update for Cyrus IMAPD
3618
3619| [66222] SLES9: Security update for Cyrus IMAPD
3620
3621| [65938] SLES10: Security update for Cyrus IMAPD
3622
3623| [65723] SLES11: Security update for Cyrus IMAPD
3624
3625| [65523] SLES9: Security update for Cyrus IMAPD
3626
3627| [65479] SLES9: Security update for cyrus-imapd
3628
3629| [65094] SLES9: Security update for cyrus-imapd
3630
3631| [65010] Ubuntu USN-838-1 (dovecot)
3632
3633| [64989] CentOS Security Advisory CESA-2009:1459 (cyrus-imapd)
3634
3635| [64978] Debian Security Advisory DSA 1892-1 (dovecot)
3636
3637| [64977] Debian Security Advisory DSA 1893-1 (cyrus-imapd-2.2 kolab-cyrus-imapd)
3638
3639| [64965] Fedora Core 11 FEDORA-2009-9901 (cyrus-imapd)
3640
3641| [64963] Fedora Core 10 FEDORA-2009-9869 (cyrus-imapd)
3642
3643| [64953] Mandrake Security Advisory MDVSA-2009:242-1 (dovecot)
3644
3645| [64952] Mandrake Security Advisory MDVSA-2009:242 (dovecot)
3646
3647| [64898] FreeBSD Ports: cyrus-imapd
3648
3649| [64864] Debian Security Advisory DSA 1881-1 (cyrus-imapd-2.2)
3650
3651| [64861] Fedora Core 10 FEDORA-2009-9559 (dovecot)
3652
3653| [64847] Fedora Core 10 FEDORA-2009-9428 (cyrus-imapd)
3654
3655| [64846] Fedora Core 11 FEDORA-2009-9417 (cyrus-imapd)
3656
3657| [64838] Mandrake Security Advisory MDVSA-2009:229 (cyrus-imapd)
3658
3659| [64271] CentOS Security Advisory CESA-2009:1116 (cyrus-imapd)
3660
3661| [62965] Gentoo Security Advisory GLSA 200812-16 (dovecot)
3662
3663| [62854] FreeBSD Ports: dovecot-managesieve
3664
3665| [61916] FreeBSD Ports: dovecot
3666
3667| [60588] Gentoo Security Advisory GLSA 200803-25 (dovecot)
3668
3669| [60568] Debian Security Advisory DSA 1516-1 (dovecot)
3670
3671| [60528] FreeBSD Ports: dovecot
3672
3673| [60134] Debian Security Advisory DSA 1457-1 (dovecot)
3674
3675| [60089] FreeBSD Ports: dovecot
3676
3677| [58578] Debian Security Advisory DSA 1359-1 (dovecot)
3678
3679| [56834] Debian Security Advisory DSA 1080-1 (dovecot)
3680
3681| [55807] Slackware Advisory SSA:2005-310-06 imapd
3682
3683| [54861] Gentoo Security Advisory GLSA 200502-29 (cyrus-imapd)
3684
3685| [54755] Gentoo Security Advisory GLSA 200411-34 (cyrus-imapd)
3686
3687| [53739] Debian Security Advisory DSA 215-1 (cyrus-imapd)
3688
3689| [53288] Debian Security Advisory DSA 597-1 (cyrus-imapd)
3690
3691| [52297] FreeBSD Ports: cyrus-imapd
3692
3693| [52296] FreeBSD Ports: cyrus-imapd
3694
3695| [52295] FreeBSD Ports: cyrus-imapd
3696
3697| [52294] FreeBSD Ports: cyrus-imapd
3698
3699| [52172] FreeBSD Ports: cyrus-imapd
3700
3701|_
3702
3703995/tcp open ssl/pop3 Dovecot pop3d
3704
3705| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
3706
3707| [9807] Dovecot up to 1.2.7 on Exim Input Sanitizer MAIL FROM privilege escalation
3708
3709| [7062] Dovecot 2.1.10 lib-storage/mail-search.c denial of service
3710
3711|
3712
3713| MITRE CVE - http://cve.mitre.org:
3714
3715| [CVE-2011-4318] Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
3716
3717| [CVE-2011-2167] script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
3718
3719| [CVE-2011-2166] script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
3720
3721| [CVE-2011-1929] lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
3722
3723| [CVE-2010-4011] Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
3724
3725| [CVE-2010-3780] Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
3726
3727| [CVE-2010-3779] Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
3728
3729| [CVE-2010-3707] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
3730
3731| [CVE-2010-3706] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
3732
3733| [CVE-2010-3304] The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
3734
3735| [CVE-2010-0745] Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.
3736
3737| [CVE-2010-0535] Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
3738
3739| [CVE-2010-0433] The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
3740
3741| [CVE-2009-3897] Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
3742
3743| [CVE-2009-3235] Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
3744
3745| [CVE-2009-2632] Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
3746
3747| [CVE-2008-5301] Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
3748
3749| [CVE-2008-4907] The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
3750
3751| [CVE-2008-4870] dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
3752
3753| [CVE-2008-4578] The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
3754
3755| [CVE-2008-4577] The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
3756
3757| [CVE-2008-1218] Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.
3758
3759| [CVE-2008-1199] Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
3760
3761| [CVE-2007-6598] Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
3762
3763| [CVE-2007-5794] Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
3764
3765| [CVE-2007-4211] The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
3766
3767| [CVE-2007-2231] Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
3768
3769| [CVE-2007-2173] Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
3770
3771| [CVE-2007-0618] Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
3772
3773| [CVE-2006-5973] Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
3774
3775| [CVE-2006-2502] Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
3776
3777| [CVE-2006-2414] Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
3778
3779| [CVE-2006-0730] Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
3780
3781| [CVE-2002-0925] Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.
3782
3783| [CVE-2001-0143] vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.
3784
3785| [CVE-2000-1197] POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.
3786
3787| [CVE-1999-1445] Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.
3788
3789|
3790
3791| OSVDB - http://www.osvdb.org:
3792
3793| [96172] Dovecot POP3 Service Terminated LIST Command Remote DoS
3794
3795| [93525] Dovecot IMAP APPEND Command Malformed Parameter Parsing Remote DoS
3796
3797| [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
3798
3799| [88058] Dovecot lib-storage/mail-search.c Multiple Keyword Search Handling Remote DoS
3800
3801| [77185] Dovecot SSL Certificate Common Name Field MitM Spoofing Weakness
3802
3803| [74515] Dovecot script-login chroot Configuration Setting Traversal Arbitrary File Access
3804
3805| [74514] Dovecot script-login User / Group Configuration Settings Remote Access Restriction Bypass
3806
3807| [72495] Dovecot lib-mail/message-header-parser.c Mail Header Name NULL Character Handling Remote DoS
3808
3809| [69260] Apple Mac OS X Server Dovecot Memory Aliasing Mail Delivery Issue
3810
3811| [68516] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition User Private Namespace Mailbox Access Restriction Remote Bypass
3812
3813| [68515] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition Specific Entry Order Mailbox Access Restriction Remote Bypass
3814
3815| [68513] Dovecot Non-public Namespace Mailbox ACL Manipulation Access Restriction Remote Bypass
3816
3817| [68512] Dovecot IMAP / POP3 Session Disconnect Master Process Outage Remote DoS
3818
3819| [66625] Dovecot ACL Plugin INBOX ACL Copying Weakness Restriction Bypass
3820
3821| [66113] Dovecot Mail Root Directory Creation Permission Weakness
3822
3823| [66112] Dovecot Installation base_dir Parent Directory Permission Weakness
3824
3825| [66111] Dovecot SEARCH Functionality str_find_init() Function Overflow
3826
3827| [66110] Dovecot Multiple Unspecified Buffer Overflows
3828
3829| [66108] Dovecot Malformed Message Body Processing Unspecified Functions Remote DoS
3830
3831| [64783] Dovecot E-mail Message Header Unspecified DoS
3832
3833| [63372] Apple Mac OS X Dovecot Kerberos Authentication SACL Restriction Bypass
3834
3835| [62796] Dovecot mbox Format Email Header Handling DoS
3836
3837| [60316] Dovecot base_dir Directory Permission Weakness Local Privilege Escalation
3838
3839| [58103] Dovecot CMU Sieve Plugin Script Handling Multiple Overflows
3840
3841| [50253] Dovecot dovecot.conf Permission Weakness Local ssl_key_password Parameter Disclosure
3842
3843| [49918] Dovecot ManageSieve Script Name Handling Traversal Arbitrary File Manipulation
3844
3845| [49429] Dovecot Message Parsing Feature Crafted Email Header Handling Remote DoS
3846
3847| [49099] Dovecot ACL Plugin k Right Mailbox Creation Restriction Bypass
3848
3849| [49098] Dovecot ACL Plugin Negative Access Rights Bypass
3850
3851| [43137] Dovecot mail_extra_groups Symlink File Manipulation
3852
3853| [42979] Dovecot passdbs Argument Injection Authentication Bypass
3854
3855| [39876] Dovecot LDAP Auth Cache Security Bypass
3856
3857| [39386] Dovecot ACL Plugin Insert Right APPEND / COPY Command Unauthorized Flag Manipulation
3858
3859| [35489] Dovecot index/mbox/mbox-storage.c Traversal Arbitrary Gzip File Access
3860
3861| [30524] Dovecot IMAP/POP3 Server dovecot.index.cache Handling Overflow
3862
3863| [25853] Cyrus IMAPD pop3d USER Command Remote Overflow
3864
3865| [25727] Dovecot Multiple Command Traversal Arbitrary Directory Listing
3866
3867| [23281] Dovecot imap/pop3-login dovecot-auth DoS
3868
3869| [23280] Dovecot Malformed APPEND Command DoS
3870
3871| [14459] mmmail mmpop3d USER Command mmsyslog Function Format String
3872
3873| [12033] Slackware Linux imapd/ipop3d Malformed USER/PASS Sequence DoS
3874
3875| [5857] Linux pop3d Arbitrary Mail File Access
3876
3877| [2471] akpop3d username SQL Injection
3878
3879|
3880
3881| SecurityFocus - http://www.securityfocus.com/bid/:
3882
3883| [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
3884
3885| [60052] Dovecot 'APPEND' Parameter Denial of Service Vulnerability
3886
3887| [56759] RETIRED: Dovecot 'mail-search.c' Denial of Service Vulnerability
3888
3889| [50709] Dovecot SSL Certificate 'Common Name' Field Validation Security Bypass Vulnerability
3890
3891| [48003] Dovecot 'script-login' Multiple Security Bypass Vulnerabilities
3892
3893| [47930] Dovecot Header Name NULL Character Denial of Service Vulnerability
3894
3895| [44874] Apple Mac OS X Dovecot (CVE-2010-4011) Memory Corruption Vulnerability
3896
3897| [43690] Dovecot Access Control List (ACL) Multiple Remote Vulnerabilities
3898
3899| [41964] Dovecot Access Control List (ACL) Plugin Security Bypass Weakness
3900
3901| [39838] tpop3d Remote Denial of Service Vulnerability
3902
3903| [39258] Dovecot Service Control Access List Security Bypass Vulnerability
3904
3905| [37084] Dovecot Insecure 'base_dir' Permissions Local Privilege Escalation Vulnerability
3906
3907| [36377] Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
3908
3909| [32582] Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
3910
3911| [31997] Dovecot Invalid Message Address Parsing Denial of Service Vulnerability
3912
3913| [31587] Dovecot ACL Plugin Multiple Security Bypass Vulnerabilities
3914
3915| [28181] Dovecot 'Tab' Character Password Check Security Bypass Vulnerability
3916
3917| [28092] Dovecot 'mail_extra_groups' Insecure Settings Local Unauthorized Access Vulnerability
3918
3919| [27093] Dovecot Authentication Cache Security Bypass Vulnerability
3920
3921| [25182] Dovecot ACL Plugin Security Bypass Vulnerability
3922
3923| [23552] Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
3924
3925| [22262] IBM AIX Pop3D/Pop3DS/IMapD/IMapDS Authentication Bypass Vulnerability
3926
3927| [21183] Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
3928
3929| [18056] Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
3930
3931| [17961] Dovecot Remote Information Disclosure Vulnerability
3932
3933| [16672] Dovecot Double Free Denial of Service Vulnerability
3934
3935| [8495] akpop3d User Name SQL Injection Vulnerability
3936
3937| [8473] Vpop3d Remote Denial Of Service Vulnerability
3938
3939| [3990] ZPop3D Bad Login Logging Failure Vulnerability
3940
3941| [2781] DynFX MailServer POP3d Denial of Service Vulnerability
3942
3943|
3944
3945| SecurityTracker - http://www.securitytracker.com:
3946
3947| [1028585] Dovecot APPEND Parameter Processing Flaw Lets Remote Authenticated Users Deny Service
3948
3949| [1024740] Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User
3950
3951| [1017288] Dovecot POP3/IMAP Cache File Buffer Overflow May Let Remote Users Execute Arbitrary Code
3952
3953|
3954
3955| IBM X-Force - http://xforce.iss.net:
3956
3957| [86382] Dovecot POP3 Service denial of service
3958
3959| [84396] Dovecot IMAP APPEND denial of service
3960
3961| [80453] Dovecot mail-search.c denial of service
3962
3963| [71354] Dovecot SSL Common Name (CN) weak security
3964
3965| [67675] Dovecot script-login security bypass
3966
3967| [67674] Dovecot script-login directory traversal
3968
3969| [67589] Dovecot header name denial of service
3970
3971| [63267] Apple Mac OS X Dovecot information disclosure
3972
3973| [62340] Dovecot mailbox security bypass
3974
3975| [62339] Dovecot IMAP or POP3 denial of service
3976
3977| [62256] Dovecot mailbox security bypass
3978
3979| [62255] Dovecot ACL entry security bypass
3980
3981| [60639] Dovecot ACL plugin weak security
3982
3983| [57267] Apple Mac OS X Dovecot Kerberos security bypass
3984
3985| [56763] Dovecot header denial of service
3986
3987| [54363] Dovecot base_dir privilege escalation
3988
3989| [53248] CMU Sieve plugin for Dovecot unspecified buffer overflow
3990
3991| [46323] Dovecot dovecot.conf information disclosure
3992
3993| [46227] Dovecot message parsing denial of service
3994
3995| [45669] Dovecot ACL mailbox security bypass
3996
3997| [45667] Dovecot ACL plugin rights security bypass
3998
3999| [41085] Dovecot TAB characters authentication bypass
4000
4001| [41009] Dovecot mail_extra_groups option unauthorized access
4002
4003| [39342] Dovecot LDAP auth cache configuration security bypass
4004
4005| [35767] Dovecot ACL plugin security bypass
4006
4007| [34082] Dovecot mbox-storage.c directory traversal
4008
4009| [30433] Dovecot IMAP/POP3 server dovecot.index.cache buffer overflow
4010
4011| [26578] Cyrus IMAP pop3d buffer overflow
4012
4013| [26536] Dovecot IMAP LIST information disclosure
4014
4015| [24710] Dovecot dovecot-auth and imap/pop3-login denial of service
4016
4017| [24709] Dovecot APPEND command denial of service
4018
4019| [13018] akpop3d authentication code SQL injection
4020
4021| [7345] Slackware Linux imapd and ipop3d core dump
4022
4023| [6269] imap, ipop2d and ipop3d buffer overflows
4024
4025| [5923] Linuxconf vpop3d symbolic link
4026
4027| [4918] IPOP3D, Buffer overflow attack
4028
4029| [1560] IPOP3D, user login successful
4030
4031| [1559] IPOP3D user login to remote host successful
4032
4033| [1525] IPOP3D, user logout
4034
4035| [1524] IPOP3D, user auto-logout
4036
4037| [1523] IPOP3D, user login failure
4038
4039| [1522] IPOP3D, brute force attack
4040
4041| [1521] IPOP3D, user kiss of death logout
4042
4043| [418] pop3d mktemp creates insecure temporary files
4044
4045|
4046
4047| Exploit-DB - http://www.exploit-db.com:
4048
4049| [25297] Dovecot with Exim sender_address Parameter - Remote Command Execution
4050
4051| [23053] Vpop3d Remote Denial Of Service Vulnerability
4052
4053| [16836] Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
4054
4055| [11893] tPop3d 1.5.3 DoS
4056
4057| [5257] Dovecot IMAP 1.0.10 <= 1.1rc2 Remote Email Disclosure Exploit
4058
4059| [2185] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (3)
4060
4061| [2053] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (2)
4062
4063| [1813] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit
4064
4065|
4066
4067| OpenVAS (Nessus) - http://www.openvas.org:
4068
4069| [901026] Dovecot Sieve Plugin Multiple Buffer Overflow Vulnerabilities
4070
4071| [901025] Dovecot Version Detection
4072
4073| [881402] CentOS Update for dovecot CESA-2011:1187 centos5 x86_64
4074
4075| [881358] CentOS Update for dovecot CESA-2011:1187 centos4 x86_64
4076
4077| [880980] CentOS Update for dovecot CESA-2011:1187 centos5 i386
4078
4079| [880967] CentOS Update for dovecot CESA-2011:1187 centos4 i386
4080
4081| [870607] RedHat Update for dovecot RHSA-2011:0600-01
4082
4083| [870471] RedHat Update for dovecot RHSA-2011:1187-01
4084
4085| [870153] RedHat Update for dovecot RHSA-2008:0297-02
4086
4087| [863272] Fedora Update for dovecot FEDORA-2011-7612
4088
4089| [863115] Fedora Update for dovecot FEDORA-2011-7258
4090
4091| [861525] Fedora Update for dovecot FEDORA-2007-664
4092
4093| [861394] Fedora Update for dovecot FEDORA-2007-493
4094
4095| [861333] Fedora Update for dovecot FEDORA-2007-1485
4096
4097| [860845] Fedora Update for dovecot FEDORA-2008-9202
4098
4099| [860663] Fedora Update for dovecot FEDORA-2008-2475
4100
4101| [860169] Fedora Update for dovecot FEDORA-2008-2464
4102
4103| [860089] Fedora Update for dovecot FEDORA-2008-9232
4104
4105| [840950] Ubuntu Update for dovecot USN-1295-1
4106
4107| [840668] Ubuntu Update for dovecot USN-1143-1
4108
4109| [840583] Ubuntu Update for dovecot vulnerabilities USN-1059-1
4110
4111| [840335] Ubuntu Update for dovecot vulnerabilities USN-593-1
4112
4113| [840290] Ubuntu Update for dovecot vulnerability USN-567-1
4114
4115| [840234] Ubuntu Update for dovecot vulnerability USN-666-1
4116
4117| [840072] Ubuntu Update for dovecot vulnerability USN-487-1
4118
4119| [831405] Mandriva Update for dovecot MDVSA-2011:101 (dovecot)
4120
4121| [831230] Mandriva Update for dovecot MDVSA-2010:217 (dovecot)
4122
4123| [831197] Mandriva Update for dovecot MDVSA-2010:196 (dovecot)
4124
4125| [831054] Mandriva Update for dovecot MDVSA-2010:104 (dovecot)
4126
4127| [830496] Mandriva Update for dovecot MDVSA-2008:232 (dovecot)
4128
4129| [801055] Dovecot 'base_dir' Insecure Permissions Security Bypass Vulnerability
4130
4131| [800030] Dovecot ACL Plugin Security Bypass Vulnerabilities
4132
4133| [70767] Gentoo Security Advisory GLSA 201110-04 (Dovecot)
4134
4135| [70259] FreeBSD Ports: dovecot
4136
4137| [69959] Debian Security Advisory DSA 2252-1 (dovecot)
4138
4139| [66522] FreeBSD Ports: dovecot
4140
4141| [65010] Ubuntu USN-838-1 (dovecot)
4142
4143| [64978] Debian Security Advisory DSA 1892-1 (dovecot)
4144
4145| [64953] Mandrake Security Advisory MDVSA-2009:242-1 (dovecot)
4146
4147| [64952] Mandrake Security Advisory MDVSA-2009:242 (dovecot)
4148
4149| [64861] Fedora Core 10 FEDORA-2009-9559 (dovecot)
4150
4151| [62965] Gentoo Security Advisory GLSA 200812-16 (dovecot)
4152
4153| [62854] FreeBSD Ports: dovecot-managesieve
4154
4155| [61916] FreeBSD Ports: dovecot
4156
4157| [60588] Gentoo Security Advisory GLSA 200803-25 (dovecot)
4158
4159| [60568] Debian Security Advisory DSA 1516-1 (dovecot)
4160
4161| [60528] FreeBSD Ports: dovecot
4162
4163| [60134] Debian Security Advisory DSA 1457-1 (dovecot)
4164
4165| [60089] FreeBSD Ports: dovecot
4166
4167| [58578] Debian Security Advisory DSA 1359-1 (dovecot)
4168
4169| [56834] Debian Security Advisory DSA 1080-1 (dovecot)
4170
4171|_
4172
41731433/tcp filtered ms-sql-s
4174
41752049/tcp filtered nfs
4176
41773306/tcp open mysql MySQL (unauthorized)
4178
4179| vulscan: scip VulDB - http://www.scip.ch/en/?vuldb:
4180
4181| [9672] Oracle MySQL Server up to 5.6.11 XA Transactions unknown vulnerability
4182
4183| [9671] Oracle MySQL Server up to 5.5.31/5.6.11 Server Replication unknown vulnerability
4184
4185| [9670] Oracle MySQL Server up to 5.6.11 InnoDB unknown vulnerability
4186
4187| [9669] Oracle MySQL Server up to 5.6.11 Server Privileges unknown vulnerability
4188
4189| [9668] Oracle MySQL Server up to 5.5.30/5.6.10 Server Partition unknown vulnerability
4190
4191| [9667] Oracle MySQL Server up to 5.5.31 Server Parser unknown vulnerability
4192
4193| [9666] Oracle MySQL Server up to 5.5.30/5.6.10 Server Options unknown vulnerability
4194
4195| [9665] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Server Options unknown vulnerability
4196
4197| [9664] Oracle MySQL Server up to 5.6.11 Server Optimizer unknown vulnerability
4198
4199| [9663] Oracle MySQL Server up to 5.1.69/5.5.31/5.6.11 Server Optimizer unknown vulnerability
4200
4201| [9662] Oracle MySQL Server up to 5.5.30/5.6.10 Prepared Statement Handler unknown vulnerability
4202
4203| [9661] Oracle MySQL Server up to 5.6.11 InnoDB unknown vulnerability
4204
4205| [9660] Oracle MySQL Server up to 5.1.69/5.5.31/5.6.11 Full Text Search unknown vulnerability
4206
4207| [9659] Oracle MySQL Server up to 5.6.11 Data Manipulation Language unknown vulnerability
4208
4209| [9658] Oracle MySQL Server up to 5.5.31/5.6.11 Data Manipulation Language unknown vulnerability
4210
4211| [9657] Oracle MySQL Server up to 5.5.31/5.6.11 Audit Log unknown vulnerability
4212
4213| [9656] Oracle MySQL Server up to 5.6.11 MemCached unknown vulnerability
4214
4215| [9655] Oracle MySQL Server up to 5.1.69/5.5.31/5.6.11 GIS unknown vulnerability
4216
4217| [9063] Debian Linux MySQL mysql-server-5.5.postinst race condition
4218
4219| [8419] Oracle MySQL Server up to 5.5.30/5.6.9 Server Partition unknown vulnerability
4220
4221| [8418] Oracle MySQL Server up to 5.1.67/5.5.29/5.6.10 Server Locking unknown vulnerability
4222
4223| [8417] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Server Install unknown vulnerability
4224
4225| [8416] Oracle MySQL Server up to 5.1.63 Server Types unknown vulnerability
4226
4227| [8415] Oracle MySQL Server up to 5.6.10 Server Privileges unknown vulnerability
4228
4229| [8414] Oracle MySQL Server up to 5.6.10 InnoDB unknown vulnerability
4230
4231| [8413] Oracle MySQL Server up to 5.5.30/5.6.10 InnoDB unknown vulnerability
4232
4233| [8412] Oracle MySQL Server up to 5.6.10 Data Manipulation Language unknown vulnerability
4234
4235| [8411] Oracle MySQL Server up to 5.5.30/5.6.10 Stored Procedure unknown vulnerability
4236
4237| [8410] Oracle MySQL Server up to 5.1.67/5.5.29 Server XML unknown vulnerability
4238
4239| [8409] Oracle MySQL Server up to 5.5.29 Server Replication unknown vulnerability
4240
4241| [8408] Oracle MySQL Server up to 5.1.67/5.5.29 Server Partition unknown vulnerability
4242
4243| [8407] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Server Optimizer unknown vulnerability
4244
4245| [8406] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 InnoDB unknown vulnerability
4246
4247| [8405] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Information Schema unknown vulnerability
4248
4249| [8404] Oracle MySQL Server up to 5.5.29 Data Manipulation Language unknown vulnerability
4250
4251| [8403] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Data Manipulation Language unknown vulnerability
4252
4253| [8402] Oracle MySQL Server up to 5.5.29/5.6.10 Server Optimizer unknown vulnerability
4254
4255| [8401] Oracle MySQL Server up to 5.6.10 MemCached unknown vulnerability
4256
4257| [8400] Oracle MySQL Server up to 5.1.68/5.5.30/5.6.10 Server Privileges unknown vulnerability
4258
4259| [8399] Oracle MySQL Server up to 5.1.66/5.5.28 Server Privileges unknown vulnerability
4260
4261| [8398] Oracle MySQL Server up to 5.1.67/5.5.29 unknown vulnerability
4262
4263| [8397] Oracle MySQL Server up to 5.1.67/5.5.29/5.6.10 Information Schema unknown vulnerability
4264
4265| [8396] Oracle MySQL Server up to 5.1.67/5.5.29 Server Locking unknown vulnerability
4266
4267| [8395] Oracle MySQL Server up to 5.6.10 Data Manipulation Language unknown vulnerability
4268
4269| [8065] Oracle MySQL up to 5.5.27 yaSSL buffer overflow
4270
4271| [8064] Oracle MySQL up to 5.5.29 yaSSL buffer overflow
4272
4273| [8816] Wireshark up to 1.8.6 MySQL Dissector packet-mysql.c Packet denial of service
4274
4275| [8019] Oracle MySQL Representation Converter Eingabe denial of service
4276
4277| [7431] Oracle MySQL Server up to 5.5.28 Privileges unknown vulnerability
4278
4279| [7430] Oracle MySQL Server up to 5.5.28 Partition unknown vulnerability
4280
4281| [7429] Oracle MySQL Server up to 5.5.28 Optimizer unknown vulnerability
4282
4283| [7428] Oracle MySQL Server up to 5.1.66/5.5.28 Optimizer unknown vulnerability
4284
4285| [7427] Oracle MySQL Server up to 5.1.66/5.5.28 unknown vulnerability
4286
4287| [7426] Oracle MySQL Server up to 5.5.28 MyISAM unknown vulnerability
4288
4289| [7425] Oracle MySQL Server up to 5.1.66/5.5.28 InnoDB unknown vulnerability
4290
4291| [7424] Oracle MySQL Server up to 5.5.28 InnoDB unknown vulnerability
4292
4293| [7423] Oracle MySQL Server up to 5.1.66/5.5.28 Locking unknown vulnerability
4294
4295| [7422] Oracle MySQL Server up to 5.1.66/5.5.28 unknown vulnerability
4296
4297| [7421] Oracle MySQL Server up to 5.1.66/5.1.28 Replication unknown vulnerability
4298
4299| [7420] Oracle MySQL Server up to 5.1.66/5.5.28 Replication unknown vulnerability
4300
4301| [7419] Oracle MySQL Server up to 5.5.28 Stored Procedure unknown vulnerability
4302
4303| [7418] Oracle MySQL Server up to 5.1.66/5.5.28 Server Optimizer unknown vulnerability
4304
4305| [7417] Oracle MySQL Server up to 5.1.66/5.5.28 Information Schema unknown vulnerability
4306
4307| [7416] Oracle MySQL Server up to 5.1.65/5.5.27 GIS Extension unknown vulnerability
4308
4309| [7415] Oracle MySQL Server up to 5.1.66/5.5.28 Privileges unknown vulnerability
4310
4311| [7414] Oracle MySQL Server up to 5.5.28 Parser unknown vulnerability
4312
4313| [7068] Oracle MySQL Server up to 5.5.19 Authentication information disclosure
4314
4315| [7067] Oracle MySQL Server up to 5.5.19 sql/sql_acl.cc acl_get() buffer overflow
4316
4317| [7066] Oracle MySQL Server up to 5.5.19 SELECT Command Handler denial of service
4318
4319| [7065] Oracle MySQL Server up to 5.5.19 MDL_key::mdl_key_init() buffer overflow
4320
4321| [6796] Oracle MySQL Server up to 5.1.65/5.5.27 Server Installation a.out unknown vulnerability
4322
4323| [6795] Oracle MySQL Server up to 5.1.64/5.5.26 Server Replication unknown vulnerability
4324
4325| [6794] Oracle MySQL Server up to 5.1.63/5.5.25 Server Full Text Search unknown vulnerability
4326
4327| [6793] Oracle MySQL Server up to 5.5.25 unknown vulnerability
4328
4329| [6792] Oracle MySQL Server up to 5.5.26 MySQL Client unknown vulnerability
4330
4331| [6791] Oracle MySQL Server up to 5.1.65/5.5.27 Server Optimizer unknown vulnerability
4332
4333| [6790] Oracle MySQL Server up to 5.1.64/5.5.26 Server Optimizer unknown vulnerability
4334
4335| [6789] Oracle MySQL Server up to 5.5.26 unknown vulnerability
4336
4337| [6788] Oracle MySQL Server up to 5.1.63/5.5.25 InnoDB Plugin unknown vulnerability
4338
4339| [6787] Oracle MySQL Server up to 5.1.63/5.5.25 InnoDB unknown vulnerability
4340
4341| [6786] Oracle MySQL Server up to 5.5.26 MySQL Client unknown vulnerability
4342
4343| [6785] Oracle MySQL Server up to 5.1.65/5.5.27 unknown vulnerability
4344
4345| [6784] Oracle MySQL Server up to 5.1.64/5.5.26 Protocol unknown vulnerability
4346
4347| [6783] Oracle MySQL Server up to 5.1.64/5.5.26 Information Schema buffer overflow
4348
4349| [5783] Oracle MySQL Server up to 5.1.62/5.5.22 Server Optimizer unknown vulnerability
4350
4351| [5782] Oracle MySQL Server up to 5.1.62/5.5.23 Server Optimizer unknown vulnerability
4352
4353| [5781] Oracle MySQL Server up to 5.5.23 unknown vulnerability
4354
4355| [5780] Oracle MySQL Server up to 5.5.23 InnoDB unknown vulnerability
4356
4357| [5779] Oracle MySQL Server up to 5.1.62/5.5.23 GIS Extension unknown vulnerability
4358
4359| [5778] Oracle MySQL Server up to 5.5.23 Server Optimizer unknown vulnerability
4360
4361| [5635] Oracle MySQL Server up to 5.5.25 on Linux InnoDB UPDATE denial of service
4362
4363| [5503] Oracle MySQL up to 5.5.22 Password Authentication sql/password.c memcmp() unknown vulnerability
4364
4365| [5168] Oracle MySQL Server Optimizer denial of service
4366
4367| [5166] Oracle MySQL Server up to 5.5.21 Partition denial of service
4368
4369| [5165] Oracle MySQL Server up to 5.5.19 Optimizer denial of service
4370
4371| [5159] Oracle MySQL Server up to 5.1.61/5.5.21 Optimizer denial of service
4372
4373| [5158] Oracle MySQL Server up to 5.1.61/5.5.21 DML denial of service
4374
4375| [5151] Oracle MySQL Server up to 5.1.60/5.5.19 MyISAM denial of service
4376
4377| [5981] Oracle MySQL Server 5.1.62/5.5.23 Sort Order Index Calculation Handler denial of service
4378
4379| [5072] Oracle MySQL Server up to 5.5.21 unknown vulnerability
4380
4381| [4627] Oracle MySQL up to 5.5.20 buffer overflow
4382
4383| [5236] Oracle MySQL Server 5.5.x unknown vulnerability
4384
4385| [5235] Oracle MySQL Server 5.5.x unknown vulnerability
4386
4387| [5234] Oracle MySQL Server 5.5.x unknown vulnerability
4388
4389| [5233] Oracle MySQL Server 5.5.x unknown vulnerability
4390
4391| [5232] Oracle MySQL Server 5.5.x unknown vulnerability
4392
4393| [5231] Oracle MySQL Server 5.5.x unknown vulnerability
4394
4395| [5230] Oracle MySQL Server 5.5.x unknown vulnerability
4396
4397| [5229] Oracle MySQL Server 5.5.x unknown vulnerability
4398
4399| [5228] Oracle MySQL Server 5.5.x unknown vulnerability
4400
4401| [5227] Oracle MySQL Server 5.5.x unknown vulnerability
4402
4403| [5226] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4404
4405| [5225] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4406
4407| [5224] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4408
4409| [5223] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4410
4411| [5222] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4412
4413| [5221] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4414
4415| [5220] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4416
4417| [5219] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4418
4419| [5218] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4420
4421| [5217] Oracle MySQL Server 5.1.x/5.5.x unknown vulnerability
4422
4423| [5216] Oracle MySQL Server 5.0.x/5.1.x/5.5.x unknown vulnerability
4424
4425| [5215] Oracle MySQL Server 5.0.x/5.1.x/5.5.x unknown vulnerability
4426
4427| [5214] Oracle MySQL Server 5.0.x/5.1.x/5.5.x unknown vulnerability
4428
4429| [5213] Oracle MySQL Server 5.0.x/5.1.x/5.5.x unknown vulnerability
4430
4431| [5212] Oracle MySQL Server 5.0.x/5.1.x unknown vulnerability
4432
4433| [5211] Oracle MySQL Server 5.0.x/5.1.x unknown vulnerability
4434
4435| [5210] Oracle MySQL Server 5.0.x/5.1.x unknown vulnerability
4436
4437| [3499] Sun MySQL 5.x System Table Information Handler Designfehler
4438
4439| [3469] Sun MySQL 4.x/5.x InnoDB Handler denial of service
4440
4441| [2463] Sun MySQL up to 5.0.25 DML Statement Handler Designfehler
4442
4443| [2462] Sun MySQL up to 5.0.25 Databank Creation Handler Designfehler
4444
4445| [2420] Sun MySQL up to 5.0.24 MERGE Table Handler Designfehler
4446
4447| [2288] Sun MySQL up to 5.1.11 mysql_real_escape_string() Multibyte SQL Statement SQL Injection
4448
4449| [2197] Sun MySQL up to 5.0.20 Authentication Designfehler
4450
4451| [2196] Sun MySQL up to 5.0.20 Packet Handler COM_TABLE_DUMP buffer overflow
4452
4453| [2195] Sun MySQL up to 5.0.20 Error Message Handler COM_TABLE_DUMP Designfehler
4454
4455| [2065] Sun MySQL up to 5.0.18 Logging Designfehler
4456
4457| [1978] PHP up to 5.1.2 mysqli Format String
4458
4459| [1947] PHP up to 4.4.1 on Windows mysql_connect() buffer overflow
4460
4461| [1676] MySQL Eventum up to 1.6.0 Class Handler SQL Injection
4462
4463| [1675] MySQL Eventum up to 1.6.0 get_jsrs_data.php F cross site scripting
4464
4465| [1674] MySQL Eventum up to 1.6.0 list.php release cross site scripting
4466
4467| [1673] MySQL Eventum up to 1.6.0 view.php id cross site scripting
4468
4469| [1660] MySQL Eventum up to 1.5.4 PEAR XML_RPC unknown vulnerability
4470
4471| [1644] Sun MySQL up to 4.1.13 denial of service
4472
4473| [1485] Sun MySQL up to 4.1.12 Installation mysql_install_db Symlink-Schwachstelle
4474
4475| [1273] Sun MySQL up to 4.1.9 on Windows MS DOS Device Name denial of service
4476
4477| [1272] Sun MySQL up to 4.0.24 Temporary Table Handler race condition
4478
4479| [1271] Sun MySQL up to 4.0.24 udf_init() Eingabeung\xFCltigkeit
4480
4481| [1126] Sun MySQL 4.x mysqlaccess Fehlerhafte Schreibrechte
4482
4483| [882] Sun MySQL up to 4.0.21 MERGE Table Handler denial of service
4484
4485| [879] Sun MySQL up to 3.23 Table Rename Handler Fehlerhafte Schreibrechte
4486
4487| [799] Sun MySQL up to 4.0.21 Reverse DNS Handler mysql_real_connect() buffer overflow
4488
4489| [798] Sun MySQL up to 4.0.20 Fehlerhafte Leserechte
4490
4491| [747] Sun MySQL up to 5.0 sql_parse.cpp weak authentication
4492
4493| [305] Sun MySQL Authentication Code buffer overflow
4494
4495| [279] Sun MySQL up to 3.0.57/4.0.14 Password Field Handler buffer overflow
4496
4497| [244] Sun MySQL 3/4 on Windows my.ini Fehlende Verschl\xFCsselung
4498
4499| [106] Sun MySQL up to 4.0.13 libmysqlclient mysql_real_connect() buffer overflow
4500
4501|
4502
4503| MITRE CVE - http://cve.mitre.org:
4504
4505| [CVE-2013-3812] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
4506
4507| [CVE-2013-3811] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-3806.
4508
4509| [CVE-2013-3810] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA Transactions.
4510
4511| [CVE-2013-3809] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Audit Log.
4512
4513| [CVE-2013-3808] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
4514
4515| [CVE-2013-3807] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Server Privileges.
4516
4517| [CVE-2013-3806] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-3811.
4518
4519| [CVE-2013-3805] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Prepared Statements.
4520
4521| [CVE-2013-3804] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4522
4523| [CVE-2013-3802] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Full Text Search.
4524
4525| [CVE-2013-3801] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
4526
4527| [CVE-2013-3798] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote attackers to affect integrity and availability via unknown vectors related to MemCached.
4528
4529| [CVE-2013-3796] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4530
4531| [CVE-2013-3795] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
4532
4533| [CVE-2013-3794] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
4534
4535| [CVE-2013-3793] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
4536
4537| [CVE-2013-3783] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Parser.
4538
4539| [CVE-2013-3561] Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.
4540
4541| [CVE-2013-3221] The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
4542
4543| [CVE-2013-2395] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language, a different vulnerability than CVE-2013-1567.
4544
4545| [CVE-2013-2392] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4546
4547| [CVE-2013-2391] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows local users to affect confidentiality and integrity via unknown vectors related to Server Install.
4548
4549| [CVE-2013-2389] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
4550
4551| [CVE-2013-2381] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server Privileges.
4552
4553| [CVE-2013-2378] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, 5.5.29 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
4554
4555| [CVE-2013-2376] Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
4556
4557| [CVE-2013-2375] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
4558
4559| [CVE-2013-1861] MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.
4560
4561| [CVE-2013-1570] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote attackers to affect availability via unknown vectors related to MemCached.
4562
4563| [CVE-2013-1567] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language, a different vulnerability than CVE-2013-2395.
4564
4565| [CVE-2013-1566] Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
4566
4567| [CVE-2013-1555] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, and 5.5.29 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
4568
4569| [CVE-2013-1552] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
4570
4571| [CVE-2013-1548] Unspecified vulnerability in Oracle MySQL 5.1.63 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Types.
4572
4573| [CVE-2013-1544] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
4574
4575| [CVE-2013-1532] Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Information Schema.
4576
4577| [CVE-2013-1531] Unspecified vulnerability in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server Privileges.
4578
4579| [CVE-2013-1526] Unspecified vulnerability in Oracle MySQL 5.5.29 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
4580
4581| [CVE-2013-1523] Unspecified vulnerability in Oracle MySQL 5.5.29 and earlier and 5.6.10 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server Optimizer.
4582
4583| [CVE-2013-1521] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server Locking.
4584
4585| [CVE-2013-1512] Unspecified vulnerability in Oracle MySQL 5.5.29 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
4586
4587| [CVE-2013-1511] Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
4588
4589| [CVE-2013-1506] Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, 5.5.29 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Locking.
4590
4591| [CVE-2013-1502] Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.9 and earlier allows local users to affect availability via unknown vectors related to Server Partition.
4592
4593| [CVE-2013-1492] Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulnerability than CVE-2012-0553.
4594
4595| [CVE-2013-0389] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4596
4597| [CVE-2013-0386] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
4598
4599| [CVE-2013-0385] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows local users to affect confidentiality and integrity via unknown vectors related to Server Replication.
4600
4601| [CVE-2013-0384] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Information Schema.
4602
4603| [CVE-2013-0383] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote attackers to affect availability via unknown vectors related to Server Locking.
4604
4605| [CVE-2013-0375] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.1.28 and earlier, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Server Replication.
4606
4607| [CVE-2013-0371] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.
4608
4609| [CVE-2013-0368] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
4610
4611| [CVE-2013-0367] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
4612
4613| [CVE-2012-5615] MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.
4614
4615| [CVE-2012-5614] Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.
4616
4617| [CVE-2012-5613] ** DISPUTED ** MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.
4618
4619| [CVE-2012-5612] Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.
4620
4621| [CVE-2012-5611] Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.
4622
4623| [CVE-2012-5383] ** DISPUTED ** Untrusted search path vulnerability in the installation functionality in Oracle MySQL 5.5.28, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the "C:\MySQL\MySQL Server 5.5\bin" directory, which may be added to the PATH system environment variable by an administrator, as demonstrated by a Trojan horse wlbsctrl.dll file used by the "IKE and AuthIP IPsec Keying Modules" system service in Windows Vista SP1, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 Release Preview. NOTE: CVE disputes this issue because the unsafe PATH is established only by a separate administrative action that is not a default part of the MySQL installation.
4624
4625| [CVE-2012-5096] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors.
4626
4627| [CVE-2012-5060] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and earlier allows remote authenticated users to affect availability, related to GIS Extension.
4628
4629| [CVE-2012-4452] MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of a CVE-2009-4030 regression, which was not omitted in other packages and versions such as MySQL 5.0.95 in Red Hat Enterprise Linux 6.
4630
4631| [CVE-2012-4414] Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete.
4632
4633| [CVE-2012-4255] MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.
4634
4635| [CVE-2012-4254] MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.
4636
4637| [CVE-2012-4253] Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to learn/cubemail/install.php or (2) f parameter learn/cubemail/filemanagement.php, or execute arbitrary local files via a .. (dot dot) in the (3) config parameter to learn/cubemail/menu.php.
4638
4639| [CVE-2012-4252] Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove file access restriction via a deletehtaccess action, (2) drop a database via a kill value in a db action, (3) uninstall the application via a 101 value in the phase parameter to learn/cubemail/install.php, (4) delete config.php via a 2 value in the phase parameter to learn/cubemail/install.php, (5) change a password via a schutz action, or (6) execute arbitrary SQL commands via the sql_statement parameter to learn/cubemail/sql.php.
4640
4641| [CVE-2012-4251] Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php, (2) phase parameter to install.php, (3) tablename or (4) dbid parameter to sql.php, or (5) filename parameter to restore.php in learn/cubemail/.
4642
4643| [CVE-2012-3951] The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.
4644
4645| [CVE-2012-3441] The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via unspecified vectors.
4646
4647| [CVE-2012-3197] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
4648
4649| [CVE-2012-3180] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4650
4651| [CVE-2012-3177] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server.
4652
4653| [CVE-2012-3173] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin.
4654
4655| [CVE-2012-3167] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.
4656
4657| [CVE-2012-3166] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
4658
4659| [CVE-2012-3163] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
4660
4661| [CVE-2012-3160] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows local users to affect confidentiality via unknown vectors related to Server Installation.
4662
4663| [CVE-2012-3158] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Protocol.
4664
4665| [CVE-2012-3156] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server.
4666
4667| [CVE-2012-3150] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4668
4669| [CVE-2012-3149] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote authenticated users to affect confidentiality, related to MySQL Client.
4670
4671| [CVE-2012-3147] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote attackers to affect integrity and availability, related to MySQL Client.
4672
4673| [CVE-2012-3144] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server.
4674
4675| [CVE-2012-2750] Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this might be a duplicate of CVE-2012-1689, but as of 20120816, Oracle has not commented on this possibility.
4676
4677| [CVE-2012-2749] MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.
4678
4679| [CVE-2012-2122] sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
4680
4681| [CVE-2012-2102] MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
4682
4683| [CVE-2012-1757] Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
4684
4685| [CVE-2012-1756] Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated users to affect availability via unknown vectors.
4686
4687| [CVE-2012-1735] Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4688
4689| [CVE-2012-1734] Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4690
4691| [CVE-2012-1705] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4692
4693| [CVE-2012-1703] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4694
4695| [CVE-2012-1702] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote attackers to affect availability via unknown vectors.
4696
4697| [CVE-2012-1697] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.
4698
4699| [CVE-2012-1696] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4700
4701| [CVE-2012-1690] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4702
4703| [CVE-2012-1689] Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4704
4705| [CVE-2012-1688] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability, related to Server DML.
4706
4707| [CVE-2012-0937] ** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time.
4708
4709| [CVE-2012-0882] Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VulnDisco Pack Professional 9.17. NOTE: as of 20120224, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. NOTE: due to lack of details, it is not clear whether this issue is a duplicate of CVE-2012-0492 or another CVE.
4710
4711| [CVE-2012-0583] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.
4712
4713| [CVE-2012-0578] Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4714
4715| [CVE-2012-0574] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors.
4716
4717| [CVE-2012-0572] Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
4718
4719| [CVE-2012-0553] Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulnerability than CVE-2013-1492.
4720
4721| [CVE-2012-0540] Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier and 5.5.23 and earlier allows remote authenticated users to affect availability, related to GIS Extension.
4722
4723| [CVE-2012-0496] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
4724
4725| [CVE-2012-0495] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, and CVE-2012-0493.
4726
4727| [CVE-2012-0494] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows local users to affect availability via unknown vectors.
4728
4729| [CVE-2012-0493] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, and CVE-2012-0495.
4730
4731| [CVE-2012-0492] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0485.
4732
4733| [CVE-2012-0491] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0493, and CVE-2012-0495.
4734
4735| [CVE-2012-0490] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect availability via unknown vectors.
4736
4737| [CVE-2012-0489] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
4738
4739| [CVE-2012-0488] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
4740
4741| [CVE-2012-0487] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
4742
4743| [CVE-2012-0486] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
4744
4745| [CVE-2012-0485] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0492.
4746
4747| [CVE-2012-0484] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect confidentiality via unknown vectors.
4748
4749| [CVE-2012-0120] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0485, and CVE-2012-0492.
4750
4751| [CVE-2012-0119] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.
4752
4753| [CVE-2012-0118] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and availability via unknown vectors, a different vulnerability than CVE-2012-0113.
4754
4755| [CVE-2012-0117] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
4756
4757| [CVE-2012-0116] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
4758
4759| [CVE-2012-0115] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.
4760
4761| [CVE-2012-0114] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows local users to affect confidentiality and integrity via unknown vectors.
4762
4763| [CVE-2012-0113] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and availability via unknown vectors, a different vulnerability than CVE-2012-0118.
4764
4765| [CVE-2012-0112] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.
4766
4767| [CVE-2012-0102] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0087 and CVE-2012-0101.
4768
4769| [CVE-2012-0101] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0087 and CVE-2012-0102.
4770
4771| [CVE-2012-0087] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0101 and CVE-2012-0102.
4772
4773| [CVE-2012-0075] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect integrity via unknown vectors.
4774
4775| [CVE-2011-5049] MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port 3306.
4776
4777| [CVE-2011-4959] SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
4778
4779| [CVE-2011-4899] ** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor disputes the significance of this issue
4780
4781| [CVE-2011-4898] ** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue
4782
4783| [CVE-2011-3989] SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
4784
4785| [CVE-2011-3805] TaskFreak! multi-mysql-0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/language/zh/register_info.php and certain other files.
4786
4787| [CVE-2011-2688] SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
4788
4789| [CVE-2011-2531] Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remote attackers to cause a denial of service (data truncation) by sending a large amount of data.
4790
4791| [CVE-2011-2262] Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote attackers to affect availability via unknown vectors.
4792
4793| [CVE-2011-1906] Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event collection table via requests to the management port, a different vulnerability than CVE-2011-0756.
4794
4795| [CVE-2011-1513] Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.
4796
4797| [CVE-2011-0432] Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.
4798
4799| [CVE-2010-5104] The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, which allows remote attackers to obtain sensitive information via wildcard characters in a LIKE query.
4800
4801| [CVE-2010-4822] core/model/MySQLDatabase.php in SilverStripe 2.4.x before 2.4.4, when the site is running in "live mode," allows remote attackers to obtain the SQL queries for a page via the showqueries and ajax parameters.
4802
4803| [CVE-2010-4700] The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.
4804
4805| [CVE-2010-3840] The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a crafted number of (1) line strings or (2) line points.
4806
4807| [CVE-2010-3839] MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (infinite loop) via multiple invocations of a (1) prepared statement or (2) stored procedure that creates a query with nested JOIN statements.
4808
4809| [CVE-2010-3838] MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a query that uses the (1) GREATEST or (2) LEAST function with a mixed list of numeric and LONGBLOB arguments, which is not properly handled when the function's result is "processed using an intermediate temporary table."
4810
4811| [CVE-2010-3837] MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a prepared statement that uses GROUP_CONCAT with the WITH ROLLUP modifier, probably triggering a use-after-free error when a copied object is modified in a way that also affects the original object.
4812
4813| [CVE-2010-3836] MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (assertion failure and server crash) via vectors related to view preparation, pre-evaluation of LIKE predicates, and IN Optimizers.
4814
4815| [CVE-2010-3835] MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (mysqld server crash) by performing a user-variable assignment in a logical expression that is calculated and stored in a temporary table for GROUP BY, then causing the expression value to be used after the table is created, which causes the expression to be re-evaluated instead of accessing its value from the table.
4816
4817| [CVE-2010-3834] Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vectors related to "materializing a derived table that required a temporary table for grouping" and "user variable assignments."
4818
4819| [CVE-2010-3833] MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a denial of service (server crash) via crafted arguments to extreme-value functions such as (1) LEAST and (2) GREATEST, related to KILL_BAD_DATA and a "CREATE TABLE ... SELECT."
4820
4821| [CVE-2010-3683] Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a crafted request.
4822
4823| [CVE-2010-3682] Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
4824
4825| [CVE-2010-3681] Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the HANDLER interface and performing "alternate reads from two indexes on a table," which triggers an assertion failure.
4826
4827| [CVE-2010-3680] Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by creating temporary tables with nullable columns while using InnoDB, which triggers an assertion failure.
4828
4829| [CVE-2010-3679] Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLOG command, which triggers an access of uninitialized memory, as demonstrated by valgrind.
4830
4831| [CVE-2010-3678] Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.
4832
4833| [CVE-2010-3677] Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a join query that uses a table with a unique SET column.
4834
4835| [CVE-2010-3676] storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertion failure) by modifying the (1) innodb_file_format or (2) innodb_file_per_table configuration parameters for the InnoDB storage engine, then executing a DDL statement.
4836
4837| [CVE-2010-3064] Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.
4838
4839| [CVE-2010-3063] The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that cause a negative length value to be used.
4840
4841| [CVE-2010-3062] mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function
4842
4843| [CVE-2010-3056] Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.
4844
4845| [CVE-2010-2008] MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.
4846
4847| [CVE-2010-2003] Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML via the mysql_host parameter.
4848
4849| [CVE-2010-1865] Multiple SQL injection vulnerabilities in ClanSphere 2009.0.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the IP address to the cs_getip function in generate.php in the Captcha module, or (2) the s_email parameter to the cs_sql_select function in the MySQL database driver (mysql.php).
4850
4851| [CVE-2010-1850] Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.
4852
4853| [CVE-2010-1849] The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.
4854
4855| [CVE-2010-1848] Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.
4856
4857| [CVE-2010-1626] MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.
4858
4859| [CVE-2010-1621] The mysql_uninstall_plugin function in sql/sql_plugin.cc in MySQL 5.1 before 5.1.46 does not check privileges before uninstalling a plugin, which allows remote attackers to uninstall arbitrary plugins via the UNINSTALL PLUGIN command.
4860
4861| [CVE-2010-1583] SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! before 0.6.3, allows remote attackers to execute arbitrary SQL commands via the username field in a login action.
4862
4863| [CVE-2010-0336] Unspecified vulnerability in the kiddog_mysqldumper (kiddog_mysqldumper) extension 0.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.
4864
4865| [CVE-2010-0124] Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
4866
4867| [CVE-2009-5026] The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.
4868
4869| [CVE-2009-4833] MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate.
4870
4871| [CVE-2009-4484] Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.
4872
4873| [CVE-2009-4030] MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
4874
4875| [CVE-2009-4028] The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.
4876
4877| [CVE-2009-4019] mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
4878
4879| [CVE-2009-3696] Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.
4880
4881| [CVE-2009-3102] The doHotCopy subroutine in socket-server.pl in Zmanda Recovery Manager (ZRM) for MySQL 2.x before 2.1.1 allows remote attackers to execute arbitrary commands via vectors involving a crafted $MYSQL_BINPATH variable.
4882
4883| [CVE-2009-2942] The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
4884
4885| [CVE-2009-2446] Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request. NOTE: some of these details are obtained from third party information.
4886
4887| [CVE-2009-1246] Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) row_mysql_blocks_center_down[file] parameter to includes/block_center_down.php
4888
4889| [CVE-2009-1208] SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.
4890
4891| [CVE-2009-0919] XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet."
4892
4893| [CVE-2009-0819] sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.
4894
4895| [CVE-2009-0617] Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL root password, which makes it easier for remote attackers to execute arbitrary operating-system commands or change system files.
4896
4897| [CVE-2009-0543] ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.
4898
4899| [CVE-2008-7247] sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.
4900
4901| [CVE-2008-6992] GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.
4902
4903| [CVE-2008-6813] SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the id_kat parameter.
4904
4905| [CVE-2008-6812] SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter.
4906
4907| [CVE-2008-6655] Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via the (1) nom_branche and (2) nom parameters to php/prenom.php
4908
4909| [CVE-2008-6287] Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4) VideoController.php, and (5) ViewController.php in controllers/.
4910
4911| [CVE-2008-6193] Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
4912
4913| [CVE-2008-5847] Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.
4914
4915| [CVE-2008-5738] Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the nodstrumCalendarV2 cookie to 1. NOTE: some of these details are obtained from third party information.
4916
4917| [CVE-2008-5737] SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the username parameter.
4918
4919| [CVE-2008-5069] SQL injection vulnerability in go.php in Panuwat PromoteWeb MySQL, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
4920
4921| [CVE-2008-4456] Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
4922
4923| [CVE-2008-4455] Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the language cookie.
4924
4925| [CVE-2008-4454] Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the lang parameter to actions.php. NOTE: the provenance of this information is unknown
4926
4927| [CVE-2008-4180] Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a "localhost" g_dbhost parameter value, related to a "Mysql Remote Brute Force Vulnerability."
4928
4929| [CVE-2008-4106] WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.
4930
4931| [CVE-2008-4098] MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
4932
4933| [CVE-2008-4097] MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.
4934
4935| [CVE-2008-3963] MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.
4936
4937| [CVE-2008-3846] Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4938
4939| [CVE-2008-3840] Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
4940
4941| [CVE-2008-3820] Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.
4942
4943| [CVE-2008-3582] SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
4944
4945| [CVE-2008-3090] Multiple SQL injection vulnerabilities in index.php in BlognPlus (BURO GUN +) 2.5.5 MySQL and PostgreSQL editions allow remote attackers to execute arbitrary SQL commands via the (1) p, (2) e, (3) d, and (4) m parameters, a different vulnerability than CVE-2008-2819.
4946
4947| [CVE-2008-2881] Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
4948
4949| [CVE-2008-2857] AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
4950
4951| [CVE-2008-2819] SQL injection vulnerability in BlognPlus (BURO GUN +) 2.5.4 and earlier MySQL and PostgreSQL editions allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
4952
4953| [CVE-2008-2667] SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.
4954
4955| [CVE-2008-2384] SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.
4956
4957| [CVE-2008-2079] MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.
4958
4959| [CVE-2008-2029] Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary SQL commands via the xtr parameter in a userinfo action to index.php.
4960
4961| [CVE-2008-1711] Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
4962
4963| [CVE-2008-1567] phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
4964
4965| [CVE-2008-1486] SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commands via the non-fulltext search.
4966
4967| [CVE-2008-0249] PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails. NOTE: this might only be an issue in limited environments.
4968
4969| [CVE-2008-0227] yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.
4970
4971| [CVE-2008-0226] Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
4972
4973| [CVE-2007-6512] PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database information via a direct request to inc/lib.inc.
4974
4975| [CVE-2007-6418] The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.
4976
4977| [CVE-2007-6345] SQL injection vulnerability in aurora framework before 20071208 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the value parameter to the pack_var function in module/db.lib/db_mysql.lib. NOTE: some of these details are obtained from third party information.
4978
4979| [CVE-2007-6313] MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements.
4980
4981| [CVE-2007-6304] The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.
4982
4983| [CVE-2007-6303] MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.
4984
4985| [CVE-2007-6081] AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" account without a password, which allows remote attackers to gain privileges and modify logs.
4986
4987| [CVE-2007-5970] MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use of table-level DATA DIRECTORY and INDEX DIRECTORY options when creating a partitioned table with the same name as a table on which the user lacks privileges.
4988
4989| [CVE-2007-5969] MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.
4990
4991| [CVE-2007-5925] The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error.
4992
4993| [CVE-2007-5646] SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php.
4994
4995| [CVE-2007-5626] make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.
4996
4997| [CVE-2007-5488] Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to execute arbitrary SQL commands via the (1) source and (2) destination numbers, and probably (3) SIP URI, when inserting a record.
4998
4999| [CVE-2007-4889] The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.
5000
5001| [CVE-2007-3997] The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.
5002
5003| [CVE-2007-3782] MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table.
5004
5005| [CVE-2007-3781] MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.
5006
5007| [CVE-2007-3780] MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.
5008
5009| [CVE-2007-3567] MySQLDumper 1.21b through 1.23 REV227 uses a "Limit GET" statement in the .htaccess authentication mechanism, which allows remote attackers to bypass authentication requirements via HTTP POST requests.
5010
5011| [CVE-2007-2857] PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the parser_path parameter.
5012
5013| [CVE-2007-2766] lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing the process and its arguments, related to lib/backup-methods.sh.
5014
5015| [CVE-2007-2693] MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
5016
5017| [CVE-2007-2692] The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.
5018
5019| [CVE-2007-2691] MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
5020
5021| [CVE-2007-2583] The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
5022
5023| [CVE-2007-2554] Associated Press (AP) Newspower 4.0.1 and earlier uses a default blank password for the MySQL root account, which allows remote attackers to insert or modify news articles via shows.tblscript.
5024
5025| [CVE-2007-2429] ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of this information is unknown
5026
5027| [CVE-2007-2364] Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) mysql.class.php or (2) postgres.class.php in lib/db/
5028
5029| [CVE-2007-2204] Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3) theme parameter to themes/ubb/login.php.
5030
5031| [CVE-2007-2016] Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.
5032
5033| [CVE-2007-1779] Multiple SQL injection vulnerabilities in the MySQL back-end in Advanced Website Creator (AWC) before 1.9.0 might allow remote attackers to execute arbitrary SQL commands via unspecified parameters, related to use of mysql_escape_string instead of mysql_real_escape_string.
5034
5035| [CVE-2007-1778] PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
5036
5037| [CVE-2007-1548] SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.
5038
5039| [CVE-2007-1455] Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbitrary local files via (1) the userlanguage parameter to includes/load_language.php or (2) the fantasticopath parameter to includes/mysqlconfig.php and certain other files.
5040
5041| [CVE-2007-1439] PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.
5042
5043| [CVE-2007-1420] MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.
5044
5045| [CVE-2007-1167] inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.
5046
5047| [CVE-2007-1111] Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
5048
5049| [CVE-2007-0926] The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables.
5050
5051| [CVE-2007-0890] Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter.
5052
5053| [CVE-2007-0828] PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in the newsenginedir parameter.
5054
5055| [CVE-2007-0167] Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/
5056
5057| [CVE-2007-0124] Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.
5058
5059| [CVE-2006-7232] sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.
5060
5061| [CVE-2006-7194] PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PATH_COMPOSANT] parameter.
5062
5063| [CVE-2006-6948] MyODBC Japanese conversion edition 3.51.06, 2.50.29, and 2.50.25 allows remote attackers to cause a denial of service via a certain string in a response, which has unspecified impact on the MySQL database.
5064
5065| [CVE-2006-6457] tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.
5066
5067| [CVE-2006-6378] BTSaveMySql 1.2 stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain configuration and save files via direct requests.
5068
5069| [CVE-2006-6254] administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from conn_cahier_de_texte.php. NOTE: it is not clear whether the scope of this issue extends above the web document root, and whether directory traversal is the primary vulnerability.
5070
5071| [CVE-2006-5893] Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) mysql.php and (2) mysqli.php in include/classes/pear/DB/.
5072
5073| [CVE-2006-5702] Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6) tiki-directory_add_site.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-forums.php, (10) tiki-view_forum.php, (11) tiki-friends.php, (12) tiki-list_blogs.php, (13) tiki-list_faqs.php, (14) tiki-list_trackers.php, (15) tiki-list_users.php, (16) tiki-my_tiki.php, (17) tiki-notepad_list.php, (18) tiki-orphan_pages.php, (19) tiki-shoutbox.php, (20) tiki-usermenu.php, and (21) tiki-webmail_contacts.php, which reveal the information in certain database error messages.
5074
5075| [CVE-2006-5675] Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unknown impact and attack vectors, related to "MySQL Scripts need changes for security," possibly SQL injection vulnerabilities associated with these scripts.
5076
5077| [CVE-2006-5381] Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a direct request to (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysqli.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, (7) db_pgsql.inc, or (8) db_sybase.inc in the conlib/ directory.
5078
5079| [CVE-2006-5264] Cross-site scripting (XSS) vulnerability in sql.php in MysqlDumper 1.21 b6 allows remote attackers to inject arbitrary web script or HTML via the db parameter.
5080
5081| [CVE-2006-5127] Multiple cross-site scripting (XSS) vulnerabilities in Bartels Schoene ConPresso before 4.0.5a allow remote attackers to inject arbitrary web script or HTML via (1) the nr parameter in detail.php, (2) the msg parameter in db_mysql.inc.php, and (3) the pos parameter in index.php.
5082
5083| [CVE-2006-5079] PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter.
5084
5085| [CVE-2006-5065] PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[lib][db][path] parameter.
5086
5087| [CVE-2006-5029] SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report was disputed by a third party for 2.3.3 and 2.3.4.
5088
5089| [CVE-2006-5027] Jeroen Vennegoor JevonCMS, possibly pre alpha, allows remote attackers to obtain sensitive information via a direct request for php/main/phplib files (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysql.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, and (7) db_pgsql.inc
5090
5091| [CVE-2006-5014] Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
5092
5093| [CVE-2006-4994] Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted "Program Files" pathname.
5094
5095| [CVE-2006-4835] Bluview Blue Magic Board (BMB) (aka BMForum) 5.5 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) db_mysql_error.php, (4) langlist.php, (5) sendmail.php, or (6) style.php, which reveals the path in various error messages.
5096
5097| [CVE-2006-4578] export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain sensitive information.
5098
5099| [CVE-2006-4380] MySQL before 4.1.13 allows local users to cause a denial of service (persistent replication slave crash) via a query with multiupdate and subselects.
5100
5101| [CVE-2006-4277] Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to (1) include/novalib/class.novaAdmin.mysql.php and (2) novalib/class.novaRead.mysql.php. NOTE: the provenance of this information is unknown
5102
5103| [CVE-2006-4276] PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.
5104
5105| [CVE-2006-4227] MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.
5106
5107| [CVE-2006-4226] MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions.
5108
5109| [CVE-2006-4031] MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
5110
5111| [CVE-2006-3965] Banex PHP MySQL Banner Exchange 2.21 stores lib.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as database usernames and passwords.
5112
5113| [CVE-2006-3964] PHP remote file inclusion vulnerability in members.php in Banex PHP MySQL Banner Exchange 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_root parameter.
5114
5115| [CVE-2006-3963] Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner Exchange 2.21 allow remote attackers to execute arbitrary SQL commands via the (1) site_name parameter to (a) signup.php, and the (2) id, (3) deleteuserbanner, (4) viewmem, (5) viewmemunb, (6) viewunmem,or (7) deleteuser parameters to (b) admin.php.
5116
5117| [CVE-2006-3878] Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysql with insecure permissions, which allows local users to read the root password for the MySQL MAX database or gain privileges by modifying /etc/init.d/mysql.
5118
5119| [CVE-2006-3486] ** DISPUTED ** Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) via unspecified vectors, which triggers the overflow when the convert_dirname function is called. NOTE: the vendor has disputed this issue via e-mail to CVE, saying that it is only exploitable when the user has access to the configuration file or the Instance Manager daemon. Due to intended functionality, this level of access would already allow the user to disrupt program operation, so this does not cross security boundaries and is not a vulnerability.
5120
5121| [CVE-2006-3469] Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.
5122
5123| [CVE-2006-3330] Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title" field), (2) url, and (3) Description parameters, possibly related to issues in add1.php.
5124
5125| [CVE-2006-3329] SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter.
5126
5127| [CVE-2006-3081] mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
5128
5129| [CVE-2006-2753] SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
5130
5131| [CVE-2006-2750] Cross-site scripting (XSS) vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary web scripts or HTML via failed SQL queries, which is reflected in an error message.
5132
5133| [CVE-2006-2748] SQL injection vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary SQL commands via multiple vectors, as demonstrated by the (1) type parameter in adminfunctions.php and the (2) catalogue_id parameter in editcatalogue.php.
5134
5135| [CVE-2006-2742] SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.
5136
5137| [CVE-2006-2543] Xtreme Topsites 1.1 allows remote attackers to trigger MySQL errors and possibly conduct SQL injection attacks via unspecified vectors in join.php.
5138
5139| [CVE-2006-2329] AngelineCMS 0.6.5 and earlier allow remote attackers to obtain sensitive information via a direct request for (1) adodb-access.inc.php, (2) adodb-ado.inc.php, (3) adodb-ado_access.inc, (4) adodb-ado_mssql.inc.php, (5) adodb-borland_ibase, (6) adodb-csv.inc.php, (7) adodb-db2.inc.php, (8) adodb-fbsql.inc.php, (9) adodb-firebird.inc.php, (10) adodb-ibase.inc.php, (11) adodb-informix.inc.php, (12) adodb-informix72.inc, (13) adodb-mssql.inc.php, (14) adodb-mssqlpo.inc.php, (15) adodb-mysql.inc.php, (16) adodb-mysqlt.inc.php, (17) adodb-oci8.inc.php, (18) adodb-oci805.inc.php, (19) adodb-oci8po.inc.php, and (20) adodb-odbc.inc.php, which reveal the path in various error messages
5140
5141| [CVE-2006-2042] Adobe Dreamweaver 8 before 8.0.2 and MX 2004 can generate code that allows SQL injection attacks in the (1) ColdFusion, (2) PHP mySQL, (3) ASP, (4) ASP.NET, and (5) JSP server models.
5142
5143| [CVE-2006-1930] ** DISPUTED ** Multiple SQL injection vulnerabilities in userscript.php in Green Minute 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) huserid, (2) pituus, or (3) date parameters. NOTE: this issue has been disputed by the vendor, saying "those parameters mentioned ARE checked (preg_match) before they are used in SQL-query... If someone decided to add SQL-injection stuff to certain parameter, they would see an error text, but only because _nothing_ was passed inside that parameter (to MySQL-database)." As allowed by the vendor, CVE investigated this report on 20060525 and found that the demo site demonstrated a non-sensitive SQL error when given standard SQL injection manipulations.
5144
5145| [CVE-2006-1518] Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.
5146
5147| [CVE-2006-1517] sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.
5148
5149| [CVE-2006-1516] The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.
5150
5151| [CVE-2006-1451] MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges to that database.
5152
5153| [CVE-2006-1396] Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown
5154
5155| [CVE-2006-1395] SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown
5156
5157| [CVE-2006-1324] Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.
5158
5159| [CVE-2006-1211] IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 configures a MySQL database to allow connections from any source IP address with the ns database account, which allows remote attackers to bypass the Netcool/NeuSecure application layer and perform unauthorized database actions. NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.
5160
5161| [CVE-2006-1210] The web interface for IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 includes the MySQL database username and password in cleartext in body.phtml, which allows remote attackers to gain privileges by reading the source. NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.
5162
5163| [CVE-2006-1112] Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which displays the installation path in a MySQL error message.
5164
5165| [CVE-2006-1111] Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, which reveals usernames and passwords in a MySQL error message, possibly due to a forced SQL error or SQL injection.
5166
5167| [CVE-2006-0909] Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) class_db.php, (5) class_db_mysql.php, and (6) class_xml.php in the ips_kernel/ directory
5168
5169| [CVE-2006-0903] MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.
5170
5171| [CVE-2006-0692] Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
5172
5173| [CVE-2006-0369] ** DISPUTED ** MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views
5174
5175| [CVE-2006-0200] Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.
5176
5177| [CVE-2006-0146] The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
5178
5179| [CVE-2006-0097] Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.
5180
5181| [CVE-2006-0056] Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function. NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.
5182
5183| [CVE-2005-4713] Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP address argument to an sprintf call.
5184
5185| [CVE-2005-4661] The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.
5186
5187| [CVE-2005-4626] The default configuration of Recruitment Software installs admin/site.xml under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (MySQL database credentials) via a direct request.
5188
5189| [CVE-2005-4237] Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module.
5190
5191| [CVE-2005-2865] Multiple PHP remote file inclusion vulnerabilities in aMember Pro 2.3.4 allow remote attackers to execute arbitrary PHP code via the config[root_dir] parameter to (1) mysql.inc.php, (2) efsnet.inc.php, (3) theinternetcommerce.inc.php, (4) cdg.inc.php, (5) compuworld.inc.php, (6) directone.inc.php, (7) authorize_aim.inc.php, (8) beanstream.inc.php, (9) config.inc.php, (10) eprocessingnetwork.inc.php, (11) eway.inc.php, (12) linkpoint.inc.php, (13) logiccommerce.inc.php, (14) netbilling.inc.php, (15) payflow_pro.inc.php, (16) paymentsgateway.inc.php, (17) payos.inc.php, (18) payready.inc.php, or (19) plugnplay.inc.php.
5192
5193| [CVE-2005-2573] The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character.
5194
5195| [CVE-2005-2572] MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute arbitrary code via (1) a request for a non-library file, which causes the Windows LoadLibraryEx function to block, or (2) a request for a function in a library that has the XXX_deinit or XXX_init functions defined but is not tailored for mySQL, such as jpeg1x32.dll and jpeg2x32.dll.
5196
5197| [CVE-2005-2571] FunkBoard 0.66CF, and possibly earlier versions, does not properly restrict access to the (1) admin/mysql_install.php and (2) admin/pg_install.php scripts, which allows attackers to obtain the database username and password or inject arbitrary PHP code into info.php.
5198
5199| [CVE-2005-2558] Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.
5200
5201| [CVE-2005-2468] Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or the insert function in (7) releases.php or (8) class.release.php.
5202
5203| [CVE-2005-2467] Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.
5204
5205| [CVE-2005-2174] Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.
5206
5207| [CVE-2005-1944] xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.
5208
5209| [CVE-2005-1636] mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.
5210
5211| [CVE-2005-1274] Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter.
5212
5213| [CVE-2005-1121] Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.
5214
5215| [CVE-2005-0799] MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.
5216
5217| [CVE-2005-0711] MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.
5218
5219| [CVE-2005-0710] MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.
5220
5221| [CVE-2005-0709] MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
5222
5223| [CVE-2005-0684] Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.
5224
5225| [CVE-2005-0646] SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.
5226
5227| [CVE-2005-0544] phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exists.lib.php, (11) charset_conversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.
5228
5229| [CVE-2005-0111] Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.
5230
5231| [CVE-2005-0083] MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.
5232
5233| [CVE-2005-0082] The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash.
5234
5235| [CVE-2005-0081] MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers.
5236
5237| [CVE-2005-0004] The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
5238
5239| [CVE-2004-2632] phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
5240
5241| [CVE-2004-2398] Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.
5242
5243| [CVE-2004-2357] The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, which allows remote attackers to read or modify the backend database.
5244
5245| [CVE-2004-2354] SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
5246
5247| [CVE-2004-2149] Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.
5248
5249| [CVE-2004-2138] Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Comments field.
5250
5251| [CVE-2004-1228] The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.
5252
5253| [CVE-2004-0957] Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
5254
5255| [CVE-2004-0956] MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.
5256
5257| [CVE-2004-0931] MySQL MaxDB before 7.5.00.18 allows remote attackers to cause a denial of service (crash) via an HTTP request to webdbm with high ASCII values in the Server field, which triggers an assert error in the IsAscii7 function.
5258
5259| [CVE-2004-0837] MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
5260
5261| [CVE-2004-0836] Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).
5262
5263| [CVE-2004-0835] MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
5264
5265| [CVE-2004-0628] Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scramble string.
5266
5267| [CVE-2004-0627] The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.
5268
5269| [CVE-2004-0457] The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
5270
5271| [CVE-2004-0388] The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.
5272
5273| [CVE-2004-0381] mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.
5274
5275| [CVE-2003-1480] MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.
5276
5277| [CVE-2003-1421] Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.
5278
5279| [CVE-2003-1383] WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the MySQL database username and password.
5280
5281| [CVE-2003-1331] Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.
5282
5283| [CVE-2003-0780] Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.
5284
5285| [CVE-2003-0515] SQL injection vulnerabilities in the (1) PostgreSQL or (2) MySQL authentication modules for teapop 0.3.5 and earlier allow attackers to execute arbitrary SQL and possibly gain privileges.
5286
5287| [CVE-2003-0150] MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
5288
5289| [CVE-2003-0073] Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.
5290
5291| [CVE-2002-2043] SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.
5292
5293| [CVE-2002-1952] phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable.
5294
5295| [CVE-2002-1923] The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.
5296
5297| [CVE-2002-1921] The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.
5298
5299| [CVE-2002-1809] The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers to gain unauthorized root access to the MySQL database.
5300
5301| [CVE-2002-1479] Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users modify databases as the Cacti user and possibly gain privileges.
5302
5303| [CVE-2002-1376] libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
5304
5305| [CVE-2002-1375] The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
5306
5307| [CVE-2002-1374] The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.
5308
5309| [CVE-2002-1373] Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.
5310
5311| [CVE-2002-0969] Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.
5312
5313| [CVE-2002-0229] Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.
5314
5315| [CVE-2001-1454] Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.
5316
5317| [CVE-2001-1453] Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.
5318
5319| [CVE-2001-1275] MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
5320
5321| [CVE-2001-1274] Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
5322
5323| [CVE-2001-1255] WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.
5324
5325| [CVE-2001-1226] AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.
5326
5327| [CVE-2001-1044] Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.
5328
5329| [CVE-2001-0990] Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.
5330
5331| [CVE-2001-0645] Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.
5332
5333| [CVE-2001-0407] Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
5334
5335| [CVE-2000-0981] MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
5336
5337| [CVE-2000-0957] The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.
5338
5339| [CVE-2000-0707] PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.
5340
5341| [CVE-2000-0148] MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.
5342
5343| [CVE-2000-0045] MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
5344
5345| [CVE-1999-1188] mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.
5346
5347|
5348
5349| OSVDB - http://www.osvdb.org:
5350
5351| [95337] Oracle MySQL Server XA Transactions Subcomponent Unspecified Remote DoS
5352
5353| [95336] Oracle MySQL Server Replication Subcomponent Unspecified Remote DoS
5354
5355| [95335] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS
5356
5357| [95334] Oracle MySQL Server Privileges Subcomponent Unspecified Remote Issue
5358
5359| [95333] Oracle MySQL Server Partition Subcomponent Unspecified Remote DoS
5360
5361| [95332] Oracle MySQL Server Parser Subcomponent Unspecified Remote DoS
5362
5363| [95331] Oracle MySQL Server Options Subcomponent Unspecified Remote DoS (2013-3801)
5364
5365| [95330] Oracle MySQL Server Options Subcomponent Unspecified Remote DoS (2013-3808)
5366
5367| [95329] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2013-3796)
5368
5369| [95328] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2013-3804)
5370
5371| [95327] Oracle MySQL Server Prepared Statements Subcomponent Unspecified Remote DoS
5372
5373| [95326] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS
5374
5375| [95325] Oracle MySQL Server Full Text Search Subcomponent Unspecified Remote DoS
5376
5377| [95324] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-3795)
5378
5379| [95323] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-3793)
5380
5381| [95322] Oracle MySQL Server Audit Log Subcomponent Unspecified Remote Issue
5382
5383| [95321] Oracle MySQL Server MemCached Subcomponent Unspecified Remote Issue
5384
5385| [95131] AutoMySQLBackup /usr/sbin/automysqlbackup Database Name Arbitrary Code Injection
5386
5387| [94076] Debian Linux MySQL Server mysql-server-5.5.postinst Race Condition debian.cnf Plaintext Credential Local Disclosure
5388
5389| [93505] Wireshark MySQL Dissector (packet-mysql.c) Malformed Packet Handling Infinite Loop Remote DoS
5390
5391| [93174] MySQL Crafted Derived Table Handling DoS
5392
5393| [92967] MySQL2JSON (mn_mysql2json) Extension for TYPO3 Unspecified SQL Injection
5394
5395| [92950] MySQL Running START SLAVE Statement Process Listing Plaintext Local Password Disclosure
5396
5397| [92485] Oracle MySQL Server Partition Subcomponent Unspecified Local DoS
5398
5399| [92484] Oracle MySQL Server Locking Subcomponent Unspecified Remote DoS (2013-1506)
5400
5401| [92483] Oracle MySQL Server Install Subcomponent Unspecified Local Issue
5402
5403| [92482] Oracle MySQL Server Types Subcomponent Unspecified Remote DoS
5404
5405| [92481] Oracle MySQL Server Privileges Subcomponent Unspecified Remote Issue (2013-2381)
5406
5407| [92480] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2013-1566)
5408
5409| [92479] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2013-1511)
5410
5411| [92478] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-1567)
5412
5413| [92477] Oracle MySQL Server Stored Procedure Subcomponent Unspecified Remote DoS
5414
5415| [92476] Oracle MySQL Server Replication Subcomponent Unspecified Remote DoS
5416
5417| [92475] Oracle MySQL Server Partition Subcomponent Unspecified Remote DoS
5418
5419| [92474] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS
5420
5421| [92473] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2013-2389)
5422
5423| [92472] Oracle MySQL Server Information Schema Subcomponent Unspecified Remote DoS
5424
5425| [92471] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-1512)
5426
5427| [92470] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-1544)
5428
5429| [92469] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote Issue
5430
5431| [92468] Oracle MySQL Server MemCached Subcomponent Unspecified Remote DoS
5432
5433| [92467] Oracle MySQL Server Privileges Subcomponent Unspecified Remote Issue (2013-2375)
5434
5435| [92466] Oracle MySQL Server Privileges Subcomponent Unspecified Remote Issue (2013-1531)
5436
5437| [92465] Oracle MySQL Server Server Subcomponent Unspecified Remote Issue
5438
5439| [92464] Oracle MySQL Server Information Schema Subcomponent Unspecified Remote Issue
5440
5441| [92463] Oracle MySQL Server Locking Subcomponent Unspecified Remote Issue (2013-1521)
5442
5443| [92462] Oracle MySQL Server Data Manipulation Language Subcomponent Unspecified Remote DoS (2013-2395)
5444
5445| [91536] Oracle MySQL yaSSL Unspecified Overflow (2012-0553)
5446
5447| [91534] Oracle MySQL yaSSL Unspecified Overflow (2013-1492)
5448
5449| [91415] MySQL Raw Geometry Object String Conversion Remote DoS
5450
5451| [91108] Juju mysql Charm Install Script mysql.passwd MySQL Password Plaintext Local Disclosure
5452
5453| [89970] Site Go /site-go/admin/extra/mysql/index.php idm Parameter Traversal Arbitrary File Access
5454
5455| [89265] Oracle MySQL Server Server Privileges Subcomponent Unspecified Remote DoS
5456
5457| [89264] Oracle MySQL Server Server Partition Subcomponent Unspecified Remote DoS
5458
5459| [89263] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS (2012-0578)
5460
5461| [89262] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS (2012-1705)
5462
5463| [89261] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-0574)
5464
5465| [89260] Oracle MySQL Server MyISAM Subcomponent Unspecified Remote DoS
5466
5467| [89259] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2012-0572)
5468
5469| [89258] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS (2013-0368)
5470
5471| [89257] Oracle MySQL Server Server Locking Subcomponent Unspecified Remote DoS
5472
5473| [89256] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-1702)
5474
5475| [89255] Oracle MySQL Server Server Replication Subcomponent Unspecified Remote Issue
5476
5477| [89254] Oracle MySQL Server Server Replication Subcomponent Unspecified Local Issue
5478
5479| [89253] Oracle MySQL Server Stored Procedure Subcomponent Unspecified Remote DoS
5480
5481| [89252] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS
5482
5483| [89251] Oracle MySQL Server Information Schema Subcomponent Unspecified Remote DoS
5484
5485| [89250] Oracle MySQL Server GIS Extension Subcomponent Unspecified Remote DoS
5486
5487| [89042] ViciBox Server MySQL cron Service Default Credentials
5488
5489| [88415] Oracle MySQL Server COM_CHANGE_USER Account Password Brute-Force Weakness
5490
5491| [88118] Oracle MySQL Server FILE Privilege Database Privilege Escalation
5492
5493| [88067] Oracle MySQL Server Authentication Error Message User Enumeration
5494
5495| [88066] Oracle MySQL Server for Linux Access Rights Checking Routine Database Name Handling Stack Buffer Overflow
5496
5497| [88065] Oracle MySQL Server COM_BINLOG_DUMP Invalid Data Handling DoS
5498
5499| [88064] Oracle MySQL Server Multiple-Table DELETE Heap Buffer Overflow
5500
5501| [87704] CodeIgniter MySQL / MySQLi Driver Database Client Multi-byte Character Set Unspecified SQL Injection
5502
5503| [87507] Oracle MySQL Statement Logging Multiple Log Plaintext Local Password Disclosure
5504
5505| [87501] Oracle MySQL optimizer_switch Malformed Value Processing Local DoS
5506
5507| [87494] Oracle MySQL on Windows Field_new_decimal::store_value dbug_buff Variable Overflow DoS
5508
5509| [87480] MySQL Malformed XML Comment Handling DoS
5510
5511| [87466] MySQL SSL Certificate Revocation Weakness
5512
5513| [87356] Oracle MySQL do_div_mod DIV Expression Handling Remote DoS
5514
5515| [87355] Oracle MySQL handler::pushed_cond Table Cache Handling mysqld DoS
5516
5517| [87354] Oracle MySQL Polygon Union / Intersection Spatial Operations DoS
5518
5519| [86273] Oracle MySQL Server Server Installation Subcomponent Unspecified Local Information Disclosure
5520
5521| [86272] Oracle MySQL Server Server Replication Subcomponent Unspecified Remote DoS
5522
5523| [86271] Oracle MySQL Server Server Full Text Search Subcomponent Unspecified Remote DoS
5524
5525| [86270] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-3156)
5526
5527| [86269] Oracle MySQL Server MySQL Client Subcomponent Unspecified Remote Information Disclosure
5528
5529| [86268] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS (2012-3180)
5530
5531| [86267] Oracle MySQL Server Server Optimizer Subcomponent Unspecified Remote DoS (2012-3150)
5532
5533| [86266] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-3144)
5534
5535| [86265] Oracle MySQL Server InnoDB Plugin Subcomponent Unspecified Remote DoS
5536
5537| [86264] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS
5538
5539| [86263] Oracle MySQL Server MySQL Client Subcomponent Unspecified Remote Issue
5540
5541| [86262] Oracle MySQL Server Server Subcomponent Unspecified Remote DoS (2012-3177)
5542
5543| [86261] Oracle MySQL Server Protocol Subcomponent Unspecified Remote Issue
5544
5545| [86260] Oracle MySQL Server Information Schema Subcomponent Unspecified Remote Code Execution
5546
5547| [86175] Oracle MySQL on Windows Path Subversion Arbitrary DLL Injection Code Execution
5548
5549| [85155] Icinga module/idoutils/db/scripts/create_mysqldb.sh Icinga User Database Access Restriction Bypass
5550
5551| [84755] Oracle MySQL Sort Order Index Calculation Remote DoS
5552
5553| [84719] MySQLDumper index.php page Parameter XSS
5554
5555| [84680] MySQL Squid Access Report access.log File Path XSS
5556
5557| [83980] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2012-1689)
5558
5559| [83979] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2012-1734)
5560
5561| [83978] Oracle MySQL Server Subcomponent Unspecified Remote DoS
5562
5563| [83977] Oracle MySQL Server InnoDB Subcomponent Unspecified Remote DoS
5564
5565| [83976] Oracle MySQL Server GIS Extension Subcomponent Unspecified Remote DoS
5566
5567| [83975] Oracle MySQL Server Optimizer Subcomponent Unspecified Remote DoS (2012-1735)
5568
5569| [83661] Oracle MySQL Unspecified Issue (59533)
5570
5571| [82804] Oracle MySQL Authentication Protocol Token Comparison Casting Failure Password Bypass
5572
5573| [82803] Oracle MySQL Unspecified Issue (59387)
5574
5575| [82120] Oracle MySQL Version Specific Comment Handling Arbitrary SQL Command Execution
5576
5577| [81897] Viscacha classes/database/mysql.inc.php Multiple Parameter SQL Injection
5578
5579| [81616] MySQLDumper Multiple Script Direct Request Information Disclosure
5580
5581| [81615] MySQLDumper filemanagement.php f Parameter Traversal Arbitrary File Access
5582
5583| [81614] MySQLDumper File Upload PHP Code Execution
5584
5585| [81613] MySQLDumper main.php Multiple Function CSRF
5586
5587| [81612] MySQLDumper restore.php filename Parameter XSS
5588
5589| [81611] MySQLDumper sql.php Multiple Parameter XSS
5590
5591| [81610] MySQLDumper install.php Multiple Parameter XSS
5592
5593| [81609] MySQLDumper install.php language Parameter Traversal Arbitrary File Access
5594
5595| [81378] Oracle MySQL Server Server Optimizer Component Unspecified Remote DoS (2012-1690)
5596
5597| [81377] Oracle MySQL Server Server Optimizer Component Unspecified Remote DoS (2012-1696)
5598
5599| [81376] Oracle MySQL Server Server DML Component Unspecified Remote DoS
5600
5601| [81375] Oracle MySQL Server Partition Component Unspecified Remote DoS
5602
5603| [81374] Oracle MySQL Server MyISAM Component Unspecified Remote DoS
5604
5605| [81373] Oracle MySQL Server Server Optimizer Component Unspecified Remote DoS (2012-1703)
5606
5607| [81059] Oracle MySQL Server Multiple Unspecified Issues
5608
5609| [79038] Webmin Process Listing MySQL Password Local Disclosure
5610
5611| [78919] Oracle MySQL Unspecified Pre-authentication Remote Code Execution
5612
5613| [78710] WordPress wp-admin/setup-config.php MySQL Query Saturation Brute-Force Proxy Weakness
5614
5615| [78708] WordPress wp-admin/setup-config.php MySQL Database Verification Code Injection Weakness
5616
5617| [78707] WordPress wp-admin/setup-config.php MySQL Credentials Error Message Brute-Force Weakness
5618
5619| [78394] Oracle MySQL Server Unspecified Remote DoS (2012-0493)
5620
5621| [78393] Oracle MySQL Server Unspecified Remote DoS (2012-0492)
5622
5623| [78392] Oracle MySQL Server Unspecified Remote DoS (2012-0117)
5624
5625| [78391] Oracle MySQL Server Unspecified Remote DoS (2012-0112)
5626
5627| [78390] Oracle MySQL Server Unspecified Remote DoS (2012-0495)
5628
5629| [78389] Oracle MySQL Server Unspecified Remote DoS (2012-0491)
5630
5631| [78388] Oracle MySQL Server Unspecified Remote DoS (2012-0490)
5632
5633| [78387] Oracle MySQL Server Unspecified Remote DoS (2012-0489)
5634
5635| [78386] Oracle MySQL Server Unspecified Remote DoS (2012-0488)
5636
5637| [78385] Oracle MySQL Server Unspecified Remote DoS (2012-0487)
5638
5639| [78384] Oracle MySQL Server Unspecified Remote DoS (2012-0486)
5640
5641| [78383] Oracle MySQL Server Unspecified Remote DoS (2012-0485)
5642
5643| [78382] Oracle MySQL Server Unspecified Remote DoS (2012-0120)
5644
5645| [78381] Oracle MySQL Server Unspecified Remote DoS (2012-0119)
5646
5647| [78380] Oracle MySQL Server Unspecified Remote DoS (2012-0115)
5648
5649| [78379] Oracle MySQL Server Unspecified Remote DoS (2012-0102)
5650
5651| [78378] Oracle MySQL Server Unspecified Remote DoS (2012-0101)
5652
5653| [78377] Oracle MySQL Server Unspecified Remote DoS (2012-0087)
5654
5655| [78376] Oracle MySQL Server Unspecified Remote DoS (2011-2262)
5656
5657| [78375] Oracle MySQL Server Unspecified Local DoS
5658
5659| [78374] Oracle MySQL Server Unspecified Remote Issue (2012-0075)
5660
5661| [78373] Oracle MySQL Server Unspecified Local Issue
5662
5663| [78372] Oracle MySQL Server Unspecified Remote Information Disclosure
5664
5665| [78371] Oracle MySQL Server Unspecified Remote Issue (2012-0496)
5666
5667| [78370] Oracle MySQL Server Unspecified Remote Issue (2012-0118)
5668
5669| [78369] Oracle MySQL Server Unspecified Remote Issue (2012-0116)
5670
5671| [78368] Oracle MySQL Server Unspecified Remote Issue (2012-0113)
5672
5673| [78283] Oracle MySQL NULL Pointer Dereference Packet Parsing Remote DoS
5674
5675| [77042] e107 CMS install_.php MySQL Server Name Parsing Remote PHP Code Execution
5676
5677| [77040] DBD::mysqlPP Unspecified SQL Injection
5678
5679| [75888] TaskFreak! multi-mysql Multiple Script Direct Request Path Disclosure
5680
5681| [74120] Apache HTTP Server mod_authnz_external mysql/mysql-auth.pl user Field SQL Injection
5682
5683| [73555] Prosody MySQL Value Column Invalid Data Type Handling DoS
5684
5685| [73387] Zend Framework PDO_MySql Character Set Security Bypass
5686
5687| [72836] Arctic Fox CMS Multiple Script Direct Request MySQL Settings Disclosure
5688
5689| [72660] MySQL GUI Tools Administrator / Query Browser Command Line Credentials Local Disclosure
5690
5691| [72120] DirectAdmin mysql_backups Folder MySQL Database Backup Local Disclosure
5692
5693| [71368] Accellion File Transfer Appliance Weak MySQL root Password
5694
5695| [70967] MySQL Eventum Admin User Creation CSRF
5696
5697| [70966] MySQL Eventum preferences.php full_name Parameter XSS
5698
5699| [70961] MySQL Eventum list.php Multiple Parameter XSS
5700
5701| [70960] MySQL Eventum forgot_password.php URI XSS
5702
5703| [70947] PyWebDAV DAVServer/mysqlauth.py get_userinfo() Multiple Parameter SQL Injection
5704
5705| [70610] PHP MySQLi Extension set_magic_quotes_runtime Function mysqli_fetch_assoc Function Interaction Weakness
5706
5707| [69885] SilverStripe modules/sapphire/trunk/core/model/MySQLDatabase.php showqueries Parameter SQL Command Disclosure
5708
5709| [69395] MySQL Derived Table Grouping DoS
5710
5711| [69394] MySQL Temporary Table Expression Re-Evaluation DoS
5712
5713| [69393] MySQL GROUP_CONCAT() WITH ROLLUP Modifier DoS
5714
5715| [69392] MySQL Extreme-Value Functions Mixed Arguments DoS
5716
5717| [69391] MySQL Stored Procedures / Prepared Statements Nested Joins DoS
5718
5719| [69390] MySQL Extreme-Value Functions Argument Parsing Type Error DoS
5720
5721| [69389] MySQL CONVERT_TZ() Function Empty SET Column DoS
5722
5723| [69388] MySQL InnoDB Storage Engine Table Handling Overflow
5724
5725| [69387] MySQL LIKE Predicates Pre-Evaluation DoS
5726
5727| [69001] MySQL PolyFromWKB() Function WKB Data Remote DoS
5728
5729| [69000] MySQL HANDLER Interface Unspecified READ Request DoS
5730
5731| [68997] MySQL Prepared-Statement Mode EXPLAIN DoS
5732
5733| [68996] MySQL EXPLAIN EXTENDED Statement DoS
5734
5735| [68995] MySQL GeometryCollection non-Geometry Value Assignment DoS
5736
5737| [67488] phpMyAdmin libraries/dbi/mysqli.dbi.lib.php Unspecified Parameter XSS
5738
5739| [67487] phpMyAdmin libraries/dbi/mysql.dbi.lib.php Unspecified Parameter XSS
5740
5741| [67421] PHP Mysqlnd Extension mysqlnd_wireprotocol.c php_mysqlnd_rset_header_read Function Overflow
5742
5743| [67420] PHP Mysqlnd Extension mysqlnd_wireprotocol.c php_mysqlnd_ok_read Function Arbitrary Memory Content Disclosure
5744
5745| [67419] PHP Mysqlnd Extension php_mysqlnd_read_error_from_line Function Negative Buffer Length Value Overflow
5746
5747| [67418] PHP Mysqlnd Extension php_mysqlnd_auth_write Function Multiple Overflows
5748
5749| [67384] MySQL LOAD DATA INFILE Statement Incorrect OK Packet DoS
5750
5751| [67383] MySQL EXPLAIN Statement Item_singlerow_subselect::store Function NULL Dereference DoS
5752
5753| [67381] MySQL InnoDB Temporary Table Handling DoS
5754
5755| [67380] MySQL BINLOG Statement Unspecified Argument DoS
5756
5757| [67379] MySQL Multiple Operation NULL Argument Handling DoS
5758
5759| [67378] MySQL Unique SET Column Join Statement Remote DoS
5760
5761| [67377] MySQL DDL Statement Multiple Configuration Parameter DoS
5762
5763| [66800] PHP Multiple mysqlnd_* Function Unspecified Overflow
5764
5765| [66799] PHP mysqlnd Error Packet Handling Multiple Overflows
5766
5767| [66731] PHP Bundled MySQL Library Unspecified Issue
5768
5769| [66665] PHP MySQL LOAD DATA LOCAL open_basedir Bypass
5770
5771| [65851] MySQL ALTER DATABASE #mysql50# Prefix Handling DoS
5772
5773| [65450] phpGraphy mysql_cleanup.php include_path Parameter Remote File Inclusion
5774
5775| [65085] MySQL Enterprise Monitor Unspecified CSRF
5776
5777| [64843] MySQL DROP TABLE Command Symlink MyISAM Table Local Data Deletion
5778
5779| [64588] MySQL sql/net_serv.cc my_net_skip_rest Function Large Packet Handling Remote DoS
5780
5781| [64587] MySQL COM_FIELD_LIST Command Packet Table Name Argument Overflow
5782
5783| [64586] MySQL COM_FIELD_LIST Command Packet Authentication Bypass
5784
5785| [64524] Advanced Poll misc/get_admin.php mysql_host Parameter XSS
5786
5787| [64447] Tirzen Framework (TZN) tzn_mysql.php Username Parameter SQL Injection Authentication Bypass
5788
5789| [64320] ClanSphere MySQL Driver s_email Parameter SQL Injection
5790
5791| [63903] MySQL sql/sql_plugin.cc mysql_uninstall_plugin Function UNINSTALL PLUGIN Command Privilege Check Weakness
5792
5793| [63115] Quicksilver Forums mysqldump Process List Database Password Disclosure
5794
5795| [62830] Employee Timeclock Software mysqldump Command-line Database Password Disclosure
5796
5797| [62640] PHP mysqli_real_escape_string() Function Error Message Path Disclosure
5798
5799| [62216] Flex MySQL Connector ActionScript SQL Query Arbitrary Code Execution
5800
5801| [61752] kiddog_mysqldumper Extension for TYPO3 Unspecified Information Disclosure
5802
5803| [61497] microTopic admin/mysql.php rating Parameter SQL Injection
5804
5805| [60665] MySQL CREATE TABLE MyISAM Table mysql_unpacked_real_data_home Local Restriction Bypass
5806
5807| [60664] MySQL sql/sql_table.cc Data Home Directory Symlink CREATE TABLE Access Restriction Bypass
5808
5809| [60516] RADIO istek scripti estafresgaftesantusyan.inc Direct Request MySQL Database Credentials Disclosure
5810
5811| [60489] MySQL GeomFromWKB() Function First Argument Geometry Value Handling DoS
5812
5813| [60488] MySQL SELECT Statement WHERE Clause Sub-query DoS
5814
5815| [60487] MySQL vio_verify_callback() Function Crafted Certificate MiTM Weakness
5816
5817| [60356] MySql Client Library (libmysqlclient) mysql_real_connect Function Local Overflow
5818
5819| [59907] MySQL on Windows bind-address Remote Connection Weakness
5820
5821| [59906] MySQL on Windows Default Configuration Logging Weakness
5822
5823| [59616] MySQL Hashed Password Weakness
5824
5825| [59609] Suckbot mod_mysql_logger Shared Object Unspecified Remote DoS
5826
5827| [59495] Cyrus SASL LDAP / MySQL Authentication Patch password Field SQL Injection Authentication Bypass
5828
5829| [59062] phpMyAdmin Extension for TYPO3 MySQL Table Name Unspecified XSS
5830
5831| [59045] phpMyAdmin Crafted MYSQL Table Name XSS
5832
5833| [59030] mysql-ocaml for MySQL mysql_real_escape_string() Function Character Escaping Weakness
5834
5835| [57587] Zmanda Recovery Manager for MySQL socket-server.pl system() Function Local Privilege Escalation
5836
5837| [57586] Zmanda Recovery Manager for MySQL socket-server.pl system() Function Remote Shell Command Execution
5838
5839| [56741] MySQL Connector/J Unicode w/ SJIS/Windows-31J Charset SQL Injection
5840
5841| [56134] Virtualmin MySQL Module Execute SQL Feature Arbitrary File Access
5842
5843| [55734] MySQL sql_parse.cc dispatch_command() Function Format String DoS
5844
5845| [55566] MySQL Connector/NET SSL Certificate Verification Weakness
5846
5847| [53525] MyBlog /config/mysqlconnection.inc Direct Request Information Disclosure
5848
5849| [53524] blog+ includes/window_top.php row_mysql_bloginfo[theme] Parameter Traversal Local File Inclusion
5850
5851| [53523] blog+ includes/block_center_down.php row_mysql_blocks_center_down[file] Parameter Traversal Local File Inclusion
5852
5853| [53522] blog+ includes/block_center_top.php row_mysql_blocks_center_top[file] Parameter Traversal Local File Inclusion
5854
5855| [53521] blog+ includes/block_left.php row_mysql_blocks_left[file] Parameter Traversal Local File Inclusion
5856
5857| [53520] blog+ includes/block_right.php row_mysql_blocks_right[file] Parameter Traversal Local File Inclusion
5858
5859| [53519] blog+ includes/window_down.php row_mysql_bloginfo[theme] Parameter Traversal Local File Inclusion
5860
5861| [53366] GEDCOM_TO_MYSQL php/info.php Multiple Parameter XSS
5862
5863| [53365] GEDCOM_TO_MYSQL php/index.php nom_branche Parameter XSS
5864
5865| [53364] GEDCOM_TO_MYSQL php/prenom.php Multiple Parameter XSS
5866
5867| [53360] Blogplus includes/window_top.php row_mysql_bloginfo[theme] Parameter Traversal Local File Inclusion
5868
5869| [53359] Blogplus includes/window_down.php row_mysql_bloginfo[theme] Parameter Traversal Local File Inclusion
5870
5871| [53358] Blogplus includes/block_right.php row_mysql_blocks_right[file] Parameter Traversal Local File Inclusion
5872
5873| [53357] Blogplus includes/block_left.php row_mysql_blocks_left[file] Parameter Traversal Local File Inclusion
5874
5875| [53356] Blogplus block_center_top.php row_mysql_blocks_center_top[file] Parameter Traversal Local File Inclusion
5876
5877| [53355] Blogplus includes/block_center_down.php row_mysql_blocks_center_down[file] Parameter Traversal Local File Inclusion
5878
5879| [53110] XOOPS Cube Legacy ErrorHandler::show() Function MySQL Error Message XSS
5880
5881| [52729] Asterisk-addon cdr_addon_mysql.c Call Detail Record SQL Injection
5882
5883| [52728] Tribox cdr_addon_mysql.c Call Detail Record XSS
5884
5885| [52727] FreePBX cdr_addon_mysql.c Call Detail Record XSS
5886
5887| [52726] Areski cdr_addon_mysql.c Call Detail Record XSS
5888
5889| [52464] MySQL charset Column Truncation Weakness
5890
5891| [52453] MySQL sql/item_xmlfunc.cc ExtractValue() / UpdateXML() Functions Scalar XPath DoS
5892
5893| [52378] Cisco ANM MySQL root Account Default Password
5894
5895| [52264] Broadcast Machine MySQLController.php controllers/baseDir Parameter Remote File Inclusion
5896
5897| [51923] Apache HTTP Server mod-auth-mysql Module mod_auth_mysql.c Multibyte Character Encoding SQL Injection
5898
5899| [51171] MySQL InnoDB convert_search_mode_to_innobase Function DoS
5900
5901| [50892] MySQL Calendar index.php username Parameter SQL Injection
5902
5903| [50827] Nodstrum MySQL Calendar nodstrumCalendarV2 Cookie Manipulation Admin Authentication Bypass
5904
5905| [49875] PromoteWeb MySQL go.php id Parameter SQL Injection
5906
5907| [48710] MySQL Command Line Client HTML Output XSS
5908
5909| [48709] MySQL Quick Admin actions.php lang Parameter Traversal Local File Inclusion
5910
5911| [48708] MySQL Quick Admin index.php language Cookie Traversal Local File Inclusion
5912
5913| [48021] MySQL Empty Bit-String Literal Token SQL Statement DoS
5914
5915| [47789] mysql-lists Unspecified XSS
5916
5917| [47394] Keld PHP-MySQL News Script login.php username Parameter SQL Injection
5918
5919| [45073] MySQLDumper Extension for TYPO3 Unspecified Authentication Bypass
5920
5921| [44937] MySQL MyISAM Table CREATE TABLE Privilege Check Bypass
5922
5923| [44138] Debian GNU/Linux libdspam7-drv-mysql Cron MySQL dspam Database Password Local Disclosure
5924
5925| [44071] Phorum /include/db/mysql.php Unspecified Search SQL Injection
5926
5927| [43180] MySQL sql_select.cc INFORMATION_SCHEMA Table Crafted Query Remote DoS
5928
5929| [43179] MySQL Server BINLOG Statement Rights Checking Failure
5930
5931| [42610] MySQL DEFINER View Value Crafted Statements Remote Privilege Escalation
5932
5933| [42609] MySQL Federated Engine SHOW TABLE STATUS Query Remote DoS
5934
5935| [42608] MySQL RENAME TABLE Symlink System Table Overwrite
5936
5937| [42607] MySQL Multiple table-level DIRECTORY Remote Privilege Escalation
5938
5939| [42460] MySQLDumper HTTP POST Request Remote Authentication Bypass
5940
5941| [42423] AdventNet EventLog Analyzer MySQL Installation Default root Account
5942
5943| [41861] Bacula make_catalog_backup Function MySQL Director Password Cleartext Disclosure
5944
5945| [40232] PHP MySQL Banner Exchange inc/lib.inc Direct Request Database Disclosure
5946
5947| [40188] Password Manager Pro (PMP) mysql Unspecified Remote Command Injection
5948
5949| [39279] PHP mysql_error() Function XSS
5950
5951| [39145] aurora framework db_mysql.lib pack_var() value Parameter SQL Injection
5952
5953| [38567] NetClassifieds Mysql_db.php Halt_On_Error Setting Error Message Path Disclosure
5954
5955| [38112] Excel Parser Pro sample/xls2mysql parser_path Parameter Remote File Inclusion
5956
5957| [37880] Asterisk-Addons source/destination Numbers cdr_addon_mysql Module SQL Injection
5958
5959| [37784] PHP MySQL Extension Multiple Function Security Restriction Bypass
5960
5961| [37783] MySQL Community Server CREATE TABLE LIKE Table Structure Disclosure
5962
5963| [37782] MySQL Community Server External Table View Privilege Escalation
5964
5965| [37781] MySQL ALTER TABLE Information Disclosure
5966
5967| [37539] GPL PHP Board db.mysql.inc.php root_path Parameter Remote File Inclusion
5968
5969| [37195] Eve-Nuke Module for PHP-Nuke db/mysql.php phpbb_root_path
5970
5971| [37015] paBugs class.mysql.php path_to_bt_dir Parameter Remote File Inclusion
5972
5973| [36868] PHP MySQLi Extension LOCAL INFILE Operation Security Restriction Bypass
5974
5975| [36867] PHP MySQL Extension LOCAL INFILE Operation Security Restriction Bypass
5976
5977| [36771] InterWorx-CP SiteWorx mysql.php PATH_INFO Parameter XSS
5978
5979| [36757] InterWorx-CP NodeWorx mysql.php PATH_INFO Parameter XSS
5980
5981| [36732] MySQL Community Server Connection Protocol Malformed Password Packet Remote DoS
5982
5983| [36251] Associated Press (AP) Newspower Default MySQL root Password
5984
5985| [35168] Study Planner (Studiewijzer) db/mysql/db.inc.php SPL_CFG[dirroot] Parameter Remote File Inclusion
5986
5987| [35037] Fantastico for cPanel includes/mysqlconfig.php fantasticopath Parameter Traversal Local File Inclusion
5988
5989| [34780] Backup Manager Command Line Cleartext MySQL Password Disclosure
5990
5991| [34766] MySQL RENAME TABLE Statement Arbitrary Table Name Modification
5992
5993| [34765] MySQL mysql_change_db Function THD::db_access Privilege Escalation
5994
5995| [34734] MySQL Crafted IF Clause Divide-by-zero NULL Dereference DoS
5996
5997| [34038] MySQL Commander ressourcen/dbopen.php home Parameter Remote File Inclusion
5998
5999| [33974] MySQL information_schema Table Subselect Single-Row DoS
6000
6001| [33678] MySQLNewsEngine affichearticles.php3 newsenginedir Parameter Remote File Inclusion
6002
6003| [33447] WGS-PPC (PPC Search Engine) config/mysql_config.php INC Parameter Remote File Inclusion
6004
6005| [33372] deV!L'z Clanportal inc/filebrowser/browser.php MySQL Data Disclosure
6006
6007| [33147] ActiveCalendar data/mysqlevents.php css Parameter XSS
6008
6009| [32784] Storystream mysqli.php baseDir Parameter Remote File Inclusion
6010
6011| [32783] Storystream mysql.php baseDir Parameter Remote File Inclusion
6012
6013| [32421] Contenido CMS conlib/db_mysqli.inc Direct Request Path Disclosure
6014
6015| [32272] JevonCMS /phplib/db_mysql.inc Direct Request Path Disclosure
6016
6017| [32171] Blue Magic Board db_mysql_error.php Direct Request Path Disclosure
6018
6019| [32056] BTSaveMySql Direct Request Config File Disclosure
6020
6021| [32044] cPanel WebHost Manager (WHM) scripts/passwdmysql password Parameter XSS
6022
6023| [32024] TikiWiki tiki-wiki_rss.php ver MySQL Credential Disclosure
6024
6025| [31963] Agora MysqlfinderAdmin.php _SESSION[PATH_COMPOSANT] Parameter Remote File Inclusion
6026
6027| [31431] ZoomStats libs/dbmax/mysql.php GLOBALS[lib][db][path] Parameter Remote File Inclusion
6028
6029| [30172] TikiWiki Multiple Script Empty sort_mode Parameter MySQL Authentication Credential Disclosure
6030
6031| [29696] MySQLDumper sql.php db Parameter XSS
6032
6033| [29453] ConPresso CMS db_mysql.inc.php msg Parameter XSS
6034
6035| [29122] cPanel mysqladmin/hooksadmin Unspecified Privilege Escalation
6036
6037| [28296] MySQL Crafted multiupdate / subselects Query Local DoS
6038
6039| [28288] MySQL Instance_options::complete_initialization Function Overflow
6040
6041| [28030] Tutti Nova class.novaRead.mysql.php TNLIB_DIR Parameter Remote File Inclusion
6042
6043| [28029] Tutti Nova class.novaAdmin.mysql.php TNLIB_DIR Parameter Remote File Inclusion
6044
6045| [28028] Tutti Nova class.novaEdit.mysql.php TNLIB_DIR Parameter Remote File Inclusion
6046
6047| [28013] MySQL SUID Routine Miscalculation Arbitrary DML Statement Execution
6048
6049| [28012] MySQL Case Sensitivity Unauthorized Database Creation
6050
6051| [27919] MySQL VIEW Access information_schema.views Information Disclosure
6052
6053| [27703] MySQL MERGE Table Privilege Persistence
6054
6055| [27593] Drupal database.mysqli.inc Multiple Parameter SQL Injection
6056
6057| [27549] Opsware NAS /etc/init.d/mysqll MySQL root Cleartext Password Local Disclosure
6058
6059| [27416] MySQL Server time.cc date_format Function Format String
6060
6061| [27054] MySQL mysqld str_to_date Function NULL Argument DoS
6062
6063| [26923] PHP/MySQL Classifieds (PHP Classifieds) search.php rate Parameter SQL Injection
6064
6065| [26922] PHP/MySQL Classifieds (PHP Classifieds) AddAsset1.php Multiple Field XSS
6066
6067| [26822] Bee-hive Lite include/listall.inc.php mysqlcall Parameter Remote File Inclusion
6068
6069| [26821] Bee-hive Lite conad/include/mysqlCall.inc.php config Parameter Remote File Inclusion
6070
6071| [26820] Bee-hive Lite conad/logout.inc.php mysqlCall Parameter Remote File Inclusion
6072
6073| [26819] Bee-hive Lite conad/login.inc.php mysqlCall Parameter Remote File Inclusion
6074
6075| [26818] Bee-hive Lite conad/checkPasswd.inc.php mysqlCall Parameter Remote File Inclusion
6076
6077| [26817] Bee-hive Lite conad/changeUserDetails.inc.php mysqlCall Parameter Remote File Inclusion
6078
6079| [26816] Bee-hive Lite conad/changeEmail.inc.php mysqlCall Parameter Remote File Inclusion
6080
6081| [26125] Open Searchable Image Catalogue core.php do_mysql_query Function Error Message XSS
6082
6083| [26123] Open Searchable Image Catalogue core.php do_mysql_query Function SQL Injection
6084
6085| [25987] MySQL Multibyte Encoding SQL Injection Filter Bypass
6086
6087| [25908] Drupal database.mysql.inc Multiple Parameter SQL Injection
6088
6089| [25595] Apple Mac OS X MySQL Manager Blank root Password
6090
6091| [25228] MySQL Crafted COM_TABLE_DUMP Request Arbitrary Memory Disclosure
6092
6093| [25227] MySQL COM_TABLE_DUMP Packet Overflow
6094
6095| [25226] MySQL Malformed Login Packet Remote Memory Disclosure
6096
6097| [24245] Cholod Mysql Based Message Board Unspecified XSS
6098
6099| [24244] Cholod Mysql Based Message Board mb.cgi showmessage Action SQL Injection
6100
6101| [23963] WoltLab Burning Board class_db_mysql.php SQL Error Message XSS
6102
6103| [23915] Netcool/NeuSecure MySQL Database Connection Restriction Bypass
6104
6105| [23611] Aztek Forum index.php msg Variable Forced MySQL Error Information Disclosure
6106
6107| [23526] MySQL Query NULL Charcter Logging Bypass
6108
6109| [23157] PHP/MYSQL Timesheet changehrs.php Multiple Parameter SQL Injection
6110
6111| [23156] PHP/MYSQL Timesheet index.php Multiple Parameter SQL Injection
6112
6113| [22995] PAM-MySQL Authentication pam_get_item() Function Unspecified Privilege Escalation
6114
6115| [22994] PAM-MySQL SQL Logging Facility Segfault DoS
6116
6117| [22485] Recruitment Software admin/site.xml MySQL Authentication Credential Disclosure
6118
6119| [22479] PHP mysqli Extension Error Message Format String
6120
6121| [22232] PHP Pipe Variable mysql_connect() Function Overflow
6122
6123| [21685] MySQL Auction Search Module keyword XSS
6124
6125| [20698] Campsite notifyendsubs Cron MySQL Password Cleartext Remote Disclosure
6126
6127| [20145] Proofpoint Protection Server Embedded MySQL Server Unpassworded root Account
6128
6129| [19457] aMember Pro mysql.inc.php Remote File Inclusion
6130
6131| [19377] MAXdev MD-Pro /MySQL_Tools/admin.php Path Disclosure
6132
6133| [18899] MySQL UDF Library Arbitrary Function Load Privilege Escalation
6134
6135| [18898] MySQL UDF LoadLibraryEx Function Nonexistent Library Load DoS
6136
6137| [18897] MySQL on Windows UDF Create Function Traversal Privilege Escalation
6138
6139| [18896] MySQL User-Defined Function init_syms() Function Overflow
6140
6141| [18895] MySQL libmysqlclient.so host Parameter Remote Overflow
6142
6143| [18894] MySQL drop database Request Remote Overflow
6144
6145| [18622] FunkBoard mysql_install.php Email Field Arbitrary PHP Code Injection
6146
6147| [18620] FunkBoard mysql_install.php Admin/Database Password Manipulation
6148
6149| [18406] MySQL Eventum releases.php SQL Injection
6150
6151| [18405] MySQL Eventum custom_fields_graph.php SQL Injection
6152
6153| [18404] MySQL Eventum custom_fields.php SQL Injection
6154
6155| [18403] MySQL Eventum login.php email Parameter SQL Injection Authentication Bypass
6156
6157| [18402] MySQL Eventum get_jsrs_data.php F Parameter XSS
6158
6159| [18401] MySQL Eventum list.php release Parameter XSS
6160
6161| [18400] MySQL Eventum view.php id Parameter XSS
6162
6163| [18173] MySQL on Windows USE Command MS-DOS Device Name DoS
6164
6165| [17801] Bugzilla MySQL Replication Race Condition Information Disclosure
6166
6167| [17223] xMySQLadmin Symlink Arbitrary File Deletion
6168
6169| [16727] MySQL Nonexistent '--user' Error Incorrect Privilege Database Invocation
6170
6171| [16689] MySQL mysql_install_db Symlink Arbitrary File Overwrite
6172
6173| [16056] Plans Unspecified mySQL Remote Password Disclosure
6174
6175| [15993] MySQL MaxDB Webtool Remote getIfHeader() WebDAV Function Remote Overflow
6176
6177| [15817] MySQL MaxDB Web Tool getLockTokenHeader() Function Remote Overflow
6178
6179| [15816] MySQL MaxDB Web Administration Service Malformed GET Request Overflow
6180
6181| [15451] paNews auth.php mysql_prefix Parameter SQL Injection
6182
6183| [14748] MySQL MS-DOS Device Names Request DoS
6184
6185| [14678] MySQL CREATE FUNCTION Arbitrary libc Code Execution
6186
6187| [14677] MySQL CREATE FUNCTION mysql.func Table Arbitrary Library Injection
6188
6189| [14676] MySQL CREATE TEMPORARY TABLE Symlink Privilege Escalation
6190
6191| [14386] phpMyAdmin mysqli.dbi.lib.php Path Disclosure
6192
6193| [14052] Symantec Brightmail AntiSpam Multiple Default MySQL Accounts
6194
6195| [13086] MySQL MaxDB Web Agent Malformed HTTP Header DoS
6196
6197| [13085] MySQL MaxDB Web Agent WebDAV sapdbwa_GetUserData() Function Remote DoS
6198
6199| [13013] MySQL mysqlaccess.sh Symlink Arbitrary File Manipulation
6200
6201| [12919] MySQL MaxDB WebAgent websql Remote Overflow
6202
6203| [12779] MySQL User Defined Function Privilege Escalation
6204
6205| [12609] MySQL Eventum projects.php Multiple Parameter XSS
6206
6207| [12608] MySQL Eventum preferences.php Multiple Parameter XSS
6208
6209| [12607] MySQL Eventum forgot_password.php email Parameter XSS
6210
6211| [12606] MySQL Eventum index.php email Parameter XSS
6212
6213| [12605] MySQL Eventum Default Vendor Account
6214
6215| [12275] MySQL MaxDB Web Tools wahttp Nonexistent File Request DoS
6216
6217| [12274] MySQL MaxDB Web Tools WebDAV Handler Remote Overflow
6218
6219| [11689] Roxen Web Server MySQL Socket Permission Weakness
6220
6221| [10985] MySQL MATCH..AGAINST Query DoS
6222
6223| [10959] MySQL GRANT ALL ON Privilege Escalation
6224
6225| [10660] MySQL ALTER TABLE/RENAME Forces Old Permission Checks
6226
6227| [10659] MySQL ALTER MERGE Tables to Change the UNION DoS
6228
6229| [10658] MySQL mysql_real_connect() Function Remote Overflow
6230
6231| [10532] MySQL MaxDB webdbm Server Field DoS
6232
6233| [10491] AWS MySQLguest AWSguest.php Script Insertion
6234
6235| [10244] MySQL libmysqlclient Prepared Statements API Overflow
6236
6237| [10226] MySQLGuest AWSguest.php Multiple Field XSS
6238
6239| [9912] PHP safe_mode MySQL Database Access Restriction Bypass
6240
6241| [9911] Inter7 vpopmail MySQL Module Authentication Credential Disclosure
6242
6243| [9910] MySQL mysql_change_user() Double-free Memory Pointer DoS
6244
6245| [9909] MySQL datadir/my.cnf Modification Privilege Escalation
6246
6247| [9908] MySQL my.ini Initialization File datadir Parameter Overflow
6248
6249| [9907] MySQL SELECT Statement String Handling Overflow
6250
6251| [9906] MySQL GRANT Privilege Arbitrary Password Modification
6252
6253| [9509] teapop MySQL Authentication Module SQL Injection
6254
6255| [9018] MySQL Backup Pro getbackup() Method Unspecified Issue
6256
6257| [9015] MySQL mysqlhotcopy Insecure Temporary File Creation
6258
6259| [8997] Cacti config.php MySQL Authentication Credential Cleartext Disclosure
6260
6261| [8979] MySQL SHOW GRANTS Encrypted Password Disclosure
6262
6263| [8889] MySQL COM_TABLE_DUMP Package Negative Integer DoS
6264
6265| [8888] MySQL COM_CHANGE_USER Command Long Repsonse Overflow
6266
6267| [8887] MySQL COM_CHANGE_USER Command One Character Password Brute Force
6268
6269| [8886] MySQL libmysqlclient Library read_one_row Overflow
6270
6271| [8885] MySQL libmysqlclient Library read_rows Overflow
6272
6273| [7476] MySQL Protocol 4.1 Authentication Scramble String Overflow
6274
6275| [7475] MySQL Zero-length Scrambled String Crafted Packet Authentication Bypass
6276
6277| [7245] MySQL Pluggable Authentication Module (pam_mysql) Password Disclosure
6278
6279| [7128] MySQL show database Database Name Exposure
6280
6281| [6716] MySQL Database Engine Weak Authentication Information Disclosure
6282
6283| [6605] MySQL mysqld Readable Log File Information Disclosure
6284
6285| [6443] PowerPhlogger db_dump.php View Arbitrary mySQL Dump
6286
6287| [6421] MySQL mysqld_multi Symlink Arbitrary File Overwrite
6288
6289| [6420] MySQL mysqlbug Symlink Arbitrary File Overwrite
6290
6291| [2537] MySQL sql_acl.cc get_salt_from_password Function Password Handling Remote Overflow
6292
6293| [2144] WinMySQLadmin my.ini Cleartext Password Disclosure
6294
6295| [653] PCCS-Linux MySQL Database Admin Tool Authentication Credential Disclosure
6296
6297| [520] MySQL Database Name Traversal Arbitrary File Modification
6298
6299| [380] MySQL Server on Windows Default Null Root Password
6300
6301| [261] MySQL Short Check String Authentication Bypass
6302
6303|
6304
6305| SecurityFocus - http://www.securityfocus.com/bid/:
6306
6307| [61274] Oracle MySQL Server CVE-2013-3798 Remote Security Vulnerability
6308
6309| [61272] Oracle MySQL Server CVE-2013-3809 Remote Security Vulnerability
6310
6311| [61269] Oracle MySQL Server CVE-2013-3801 Remote Security Vulnerability
6312
6313| [61264] Oracle MySQL Server CVE-2013-3793 Remote Security Vulnerability
6314
6315| [61260] Oracle MySQL Server CVE-2013-3804 Remote Security Vulnerability
6316
6317| [61256] Oracle MySQL Server CVE-2013-3805 Remote Security Vulnerability
6318
6319| [61252] Oracle MySQL Server CVE-2013-3811 Remote Security Vulnerability
6320
6321| [61249] Oracle MySQL Server CVE-2013-3812 Remote Security Vulnerability
6322
6323| [61244] Oracle MySQL Server CVE-2013-3802 Remote Security Vulnerability
6324
6325| [61241] Oracle MySQL Server CVE-2013-3795 Remote Security Vulnerability
6326
6327| [61238] Oracle MySQL Server CVE-2013-3807 Remote Security Vulnerability
6328
6329| [61235] Oracle MySQL Server CVE-2013-3806 Remote Security Vulnerability
6330
6331| [61233] Oracle MySQL Server CVE-2013-3796 Remote Security Vulnerability
6332
6333| [61227] Oracle MySQL Server CVE-2013-3808 Remote Security Vulnerability
6334
6335| [61222] Oracle MySQL Server CVE-2013-3794 Remote Security Vulnerability
6336
6337| [61214] Oracle MySQL Server CVE-2013-3810 Remote Security Vulnerability
6338
6339| [61210] Oracle MySQL Server CVE-2013-3783 Remote Security Vulnerability
6340
6341| [60424] Debian mysql-server CVE-2013-2162 Insecure File Creation Vulnerability
6342
6343| [60001] Wireshark MySQL Dissector Denial of Service Vulnerability
6344
6345| [59242] Oracle MySQL CVE-2013-2391 Local MySQL Server Vulnerability
6346
6347| [59239] Oracle MySQL CVE-2013-1502 Local MySQL Server Vulnerability
6348
6349| [59237] Oracle MySQL CVE-2013-1506 Remote MySQL Server Vulnerability
6350
6351| [59232] Oracle MySQL CVE-2013-1567 Remote MySQL Server Vulnerability
6352
6353| [59229] Oracle MySQL Server CVE-2013-1544 Remote Security Vulnerability
6354
6355| [59227] Oracle MySQL CVE-2013-2376 Remote MySQL Server Vulnerability
6356
6357| [59225] Oracle MySQL CVE-2013-1523 Remote MySQL Server Vulnerability
6358
6359| [59224] Oracle MySQL Server CVE-2013-2392 Remote Security Vulnerability
6360
6361| [59223] Oracle MySQL Server CVE-2013-1548 Remote Security Vulnerability
6362
6363| [59222] RETIRED: Oracle MySQL CVE-2012-5614 Remote MySQL Server Vulnerability
6364
6365| [59218] Oracle MySQL Server CVE-2013-1512 Remote Security Vulnerability
6366
6367| [59217] Oracle MySQL CVE-2013-1526 Remote MySQL Server Vulnerability
6368
6369| [59216] Oracle MySQL CVE-2013-1570 Remote MySQL Server Vulnerability
6370
6371| [59215] Oracle MySQL Server CVE-2013-2381 Remote Security Vulnerability
6372
6373| [59211] Oracle MySQL Server CVE-2013-1532 Remote Security Vulnerability
6374
6375| [59210] Oracle MySQL CVE-2013-1555 Remote MySQL Server Vulnerability
6376
6377| [59209] Oracle MySQL CVE-2013-2375 Remote MySQL Server Vulnerability
6378
6379| [59207] Oracle MySQL Server CVE-2013-2389 Remote Security Vulnerability
6380
6381| [59205] Oracle MySQL Server CVE-2013-1566 Remote Security Vulnerability
6382
6383| [59202] Oracle MySQL CVE-2013-1531 Remote MySQL Server Vulnerability
6384
6385| [59201] Oracle MySQL Server CVE-2013-1511 Remote Security Vulnerability
6386
6387| [59196] Oracle MySQL CVE-2013-1552 Remote MySQL Server Vulnerability
6388
6389| [59188] Oracle MySQL CVE-2013-2378 Remote MySQL Server Vulnerability
6390
6391| [59180] Oracle MySQL CVE-2013-1521 Remote MySQL Server Vulnerability
6392
6393| [59173] Oracle MySQL CVE-2013-2395 Remote MySQL Server Vulnerability
6394
6395| [58511] MySQL and MariaDB Geometry Query Denial Of Service Vulnerability
6396
6397| [57418] Oracle MySQL Server CVE-2013-0386 Remote Security Vulnerability
6398
6399| [57417] Oracle MySQL Server CVE-2013-0389 Remote Security Vulnerability
6400
6401| [57416] Oracle MySQL Server CVE-2013-0384 Remote Security Vulnerability
6402
6403| [57415] Oracle MySQL Server CVE-2013-0371 Remote Security Vulnerability
6404
6405| [57414] Oracle MySQL Server CVE-2012-0574 Remote Security Vulnerability
6406
6407| [57412] Oracle MySQL Server CVE-2013-0385 Local Security Vulnerability
6408
6409| [57411] Oracle MySQL Server CVE-2012-5060 Remote Security Vulnerability
6410
6411| [57410] Oracle MySQL Server CVE-2012-1705 Remote Security Vulnerability
6412
6413| [57408] Oracle MySQL Server CVE-2013-0367 Remote Security Vulnerability
6414
6415| [57405] Oracle MySQL Server CVE-2013-0383 Remote Security Vulnerability
6416
6417| [57400] Oracle MySQL Server CVE-2012-5096 Remote Security Vulnerability
6418
6419| [57397] Oracle MySQL Server CVE-2013-0368 Remote Security Vulnerability
6420
6421| [57391] Oracle MySQL Server CVE-2013-0375 Remote Security Vulnerability
6422
6423| [57388] Oracle MySQL Server CVE-2012-1702 Remote Security Vulnerability
6424
6425| [57385] Oracle MySQL Server CVE-2012-0572 Remote Security Vulnerability
6426
6427| [57334] Oracle MySQL Server CVE-2012-0578 Remote Security Vulnerability
6428
6429| [56837] Oracle MySQL and MariaDB CVE-2012-5627 Insecure Salt Generation Security Bypass Weakness
6430
6431| [56791] Oracle MySQL Remote Code Execution Vulnerability
6432
6433| [56776] Oracle MySQL CVE-2012-5614 Denial of Service Vulnerability
6434
6435| [56772] Oracle MySQL Remote Code Execution Vulnerability
6436
6437| [56771] Oracle MySQL Server Privilege Escalation Vulnerability
6438
6439| [56769] Oracle MySQL and MariaDB 'acl_get()' Buffer Overflow Vulnerability
6440
6441| [56768] Oracle MySQL Server Heap Overflow Vulnerability
6442
6443| [56766] Oracle MySQL Server Username Enumeration Weakness
6444
6445| [56041] Oracle MySQL Server CVE-2012-3173 Remote MySQL Security Vulnerability
6446
6447| [56036] Oracle MySQL Server CVE-2012-3163 Remote MySQL Security Vulnerability
6448
6449| [56028] Oracle MySQL Server CVE-2012-3166 Remote Security Vulnerability
6450
6451| [56027] Oracle MySQL Server CVE-2012-3160 Local Security Vulnerability
6452
6453| [56022] Oracle MySQL Server CVE-2012-3147 Remote Security Vulnerability
6454
6455| [56021] Oracle MySQL Server CVE-2012-3197 Remote Security Vulnerability
6456
6457| [56018] Oracle MySQL Server CVE-2012-3167 Remote Security Vulnerability
6458
6459| [56017] Oracle MySQL Server CVE-2012-3158 Remote Security Vulnerability
6460
6461| [56013] Oracle MySQL Server CVE-2012-3156 Remote Security Vulnerability
6462
6463| [56008] Oracle MySQL Server CVE-2012-3144 Remote Security Vulnerability
6464
6465| [56006] Oracle MySQL Server CVE-2012-3149 Remote Security Vulnerability
6466
6467| [56005] Oracle MySQL Server CVE-2012-3177 Remote Security Vulnerability
6468
6469| [56003] Oracle MySQL Server CVE-2012-3180 Remote Security Vulnerability
6470
6471| [55990] Oracle MySQL Server CVE-2012-3150 Remote Security Vulnerability
6472
6473| [55715] MySQL MyISAM Table Symbolic Link CVE-2012-4452 Local Privilege Escalation Vulnerability
6474
6475| [55120] Oracle MySQL CVE-2012-2749 Denial Of Service Vulnerability
6476
6477| [54551] Oracle MySQL Server CVE-2012-0540 Remote Security Vulnerability
6478
6479| [54549] Oracle MySQL Server CVE-2012-1735 Remote Security Vulnerability
6480
6481| [54547] Oracle MySQL Server CVE-2012-1689 Remote Security Vulnerability
6482
6483| [54540] Oracle MySQL Server CVE-2012-1734 Remote Security Vulnerability
6484
6485| [54526] Oracle MySQL Server CVE-2012-1757 Remote Security Vulnerability
6486
6487| [54524] Oracle MySQL Server CVE-2012-1756 Remote Security Vulnerability
6488
6489| [53922] RETIRED: MySQL and MariaDB 'sql/password.c' Authentication Bypass Vulnerability
6490
6491| [53911] Oracle MySQL CVE-2012-2122 User Login Security Bypass Vulnerability
6492
6493| [53310] MySQLDumper 'menu.php' Remote PHP Code Execution Vulnerability
6494
6495| [53306] MySQLDumper Multiple Security Vulnerabilities
6496
6497| [53074] Oracle MySQL CVE-2012-1690 Remote MySQL Server Vulnerability
6498
6499| [53071] Oracle MySQL CVE-2012-1696 Remote MySQL Server Vulnerability
6500
6501| [53067] Oracle MySQL CVE-2012-1688 Remote MySQL Server Vulnerability
6502
6503| [53064] Oracle MySQL CVE-2012-1697 Remote MySQL Server Vulnerability
6504
6505| [53061] Oracle MySQL CVE-2012-0583 Remote MySQL Server Vulnerability
6506
6507| [53058] Oracle MySQL CVE-2012-1703 Remote MySQL Server Vulnerability
6508
6509| [52931] Oracle MySQL Server Multiple Unspecified Security Vulnerabilities
6510
6511| [52154] RETIRED: MySQL 5.5.20 Unspecified Remote Code Execution Vulnerability
6512
6513| [51925] MySQL Unspecified Remote Code Execution Vulnerability
6514
6515| [51526] Oracle MySQL CVE-2012-0075 Remote MySQL Server Vulnerability
6516
6517| [51525] Oracle MySQL CVE-2012-0493 Remote Vulnerability
6518
6519| [51524] Oracle MySQL Server CVE-2012-0490 Remote Security Vulnerability
6520
6521| [51523] Oracle MySQL Server CVE-2012-0494 Local Security Vulnerability
6522
6523| [51522] Oracle MySQL Server CVE-2012-0495 Remote Security Vulnerability
6524
6525| [51521] Oracle MySQL Server CVE-2012-0117 Remote MySQL Server Vulnerability
6526
6527| [51520] Oracle MySQL Server CVE-2012-0114 Local Security Vulnerability
6528
6529| [51519] Oracle MySQL Server CVE-2012-0112 Remote MySQL Server Vulnerability
6530
6531| [51518] Oracle MySQL Server CVE-2012-0491 Remote Security Vulnerability
6532
6533| [51517] Oracle MySQL CVE-2012-0120 Remote Vulnerability
6534
6535| [51516] Oracle MySQL Server CVE-2012-0492 Remote MySQL Server Vulnerability
6536
6537| [51515] Oracle MySQL Server CVE-2012-0484 Remote Security Vulnerability
6538
6539| [51514] Oracle MySQL Server CVE-2012-0486 Remote Security Vulnerability
6540
6541| [51513] Oracle MySQL Server CVE-2012-0485 Remote Security Vulnerability
6542
6543| [51512] Oracle MySQL CVE-2012-0119 Remote Vulnerability
6544
6545| [51511] Oracle MySQL CVE-2012-0118 Remote MySQL Server Vulnerability
6546
6547| [51510] Oracle MySQL Server CVE-2012-0489 Remote MySQL Server Vulnerability
6548
6549| [51509] Oracle MySQL Server CVE-2012-0087 Remote Security Vulnerability
6550
6551| [51508] Oracle MySQL CVE-2012-0116 Remote MySQL Server Vulnerability
6552
6553| [51507] Oracle MySQL Server CVE-2012-0496 Remote Security Vulnerability
6554
6555| [51506] Oracle MySQL Server CVE-2012-0488 Remote MySQL Server Vulnerability
6556
6557| [51505] Oracle MySQL Server CVE-2012-0101 Remote Security Vulnerability
6558
6559| [51504] Oracle MySQL CVE-2012-0115 Remote Vulnerability
6560
6561| [51503] Oracle MySQL Server CVE-2012-0487 Remote MySQL Server Vulnerability
6562
6563| [51502] Oracle MySQL Server CVE-2012-0102 Remote Security Vulnerability
6564
6565| [51493] Oracle MySQL CVE-2011-2262 Remote MySQL Server Vulnerability
6566
6567| [51488] Oracle MySQL CVE-2012-0113 Remote MySQL Server Vulnerability
6568
6569| [50139] DBD::mysqlPP Unspecified SQL Injection Vulnerability
6570
6571| [48466] MySQLDriverCS SQL Injection Vulnerability
6572
6573| [47919] Zend Framework 'PDO_MySql' Security Bypass Vulnerability
6574
6575| [47871] Oracle MySQL Prior to 5.1.52 Multiple Denial Of Service Vulnerabilities
6576
6577| [47693] DirectAdmin 'mysql_backup' Folder Permissions Information Disclosure Vulnerability
6578
6579| [46655] pywebdav MySQL Authentication Module SQL Injection Vulnerability
6580
6581| [46456] MySQL Eventum 'full_name' Field HTML Injection Vulnerability
6582
6583| [46380] MySQL Eventum Multiple HTML Injection Vulnerabilities
6584
6585| [46056] PHP MySQLi Extension 'set_magic_quotes_runtime' Function Security-Bypass Weakness
6586
6587| [43884] phpFK - PHP Forum Script ohne MySQL 'page_bottom.php' Local File Include Vulnerability
6588
6589| [43677] Oracle MySQL Prior to 5.1.50 Privilege Escalation Vulnerability
6590
6591| [43676] Oracle MySQL Prior to 5.1.51 Multiple Denial Of Service Vulnerabilities
6592
6593| [42646] Oracle MySQL Prior to 5.1.49 'JOIN' Statement Denial Of Service Vulnerability
6594
6595| [42643] Oracle MySQL Prior to 5.1.49 'DDL' Statements Denial Of Service Vulnerability
6596
6597| [42638] Oracle MySQL Prior to 5.1.49 Malformed 'BINLOG' Arguments Denial Of Service Vulnerability
6598
6599| [42633] Oracle MySQL 'HANDLER' interface Denial Of Service Vulnerability
6600
6601| [42625] Oracle MySQL 'LOAD DATA INFILE' Denial Of Service Vulnerability
6602
6603| [42599] Oracle MySQL 'EXPLAIN' Denial Of Service Vulnerability
6604
6605| [42598] Oracle MySQL 'TEMPORARY InnoDB' Tables Denial Of Service Vulnerability
6606
6607| [42596] Oracle MySQL Prior to 5.1.49 'WITH ROLLUP' Denial Of Service Vulnerability
6608
6609| [42586] RETIRED: Oracle MySQL Prior to 5.1.49 Multiple Denial Of Service Vulnerabilities
6610
6611| [42417] Zmanda Recovery Manager for MySQL Multiple Local Privilege Escalation Vulnerabilities
6612
6613| [41440] phpFK - PHP Forum Script ohne MySQL 'upload.php' Arbitrary File Upload Vulnerability
6614
6615| [41198] Oracle MySQL 'ALTER DATABASE' Remote Denial Of Service Vulnerability
6616
6617| [40537] MySQL Enterprise Monitor Multiple Unspecified Cross Site Request Forgery Vulnerabilities
6618
6619| [40506] RETIRED: phpGraphy 'mysql_cleanup.php' Remote File Include Vulnerability
6620
6621| [40461] PHP Mysqlnd Extension Information Disclosure and Multiple Buffer Overflow Vulnerabilities
6622
6623| [40257] Oracle MySQL DROP TABLE MyISAM Symbolic Link Local Security Bypass Vulnerability
6624
6625| [40109] Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability
6626
6627| [40106] Oracle MySQL 'COM_FIELD_LIST' Command Buffer Overflow Vulnerability
6628
6629| [40100] Oracle MySQL Malformed Packet Handling Remote Denial of Service Vulnerability
6630
6631| [40045] Advanced Poll 'mysql_host' Parameter Cross Site Scripting Vulnerability
6632
6633| [39918] FlexAppsStore Flex MySQL Connector Unauthorized Access Vulnerability
6634
6635| [39543] MySQL UNINSTALL PLUGIN Security Bypass Vulnerability
6636
6637| [38642] Timeclock Software 'mysqldump' Local Information Disclosure Vulnerability
6638
6639| [38043] MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
6640
6641| [37943] MySQL with yaSSL SSL Certificate Handling Remote Stack Buffer Overflow Vulnerability
6642
6643| [37770] TYPO3 kiddog_mysqldumper Unspecified Information Disclosure Vulnerability
6644
6645| [37640] MySQL 5.0.51a Unspecified Remote Code Execution Vulnerability
6646
6647| [37297] MySQL Multiple Remote Denial Of Service Vulnerabilities
6648
6649| [37076] MySQL OpenSSL Server Certificate yaSSL Security Bypass Vulnerability
6650
6651| [37075] MySQL MyISAM Table Symbolic Link Local Privilege Escalation Vulnerability
6652
6653| [36242] MySQL 5.x Unspecified Buffer Overflow Vulnerability
6654
6655| [35858] MySQL Connector/J Unicode Character String SQL Injection Vulnerability
6656
6657| [35609] MySQL 'sql_parse.cc' Multiple Format String Vulnerabilities
6658
6659| [35514] MySQL Connector/Net SSL Certificate Validation Security Bypass Vulnerability
6660
6661| [33972] MySQL XPath Expression Remote Denial Of Service Vulnerability
6662
6663| [33392] 'mod_auth_mysql' Package Multibyte Character Encoding SQL Injection Vulnerability
6664
6665| [32978] MySQL Calendar 'username' Parameter SQL Injection Vulnerability
6666
6667| [32914] MySQL Calendar Cookie Authentication Bypass Vulnerability
6668
6669| [32157] MySQL Quick Admin 'actions.php' Local File Include Vulnerability
6670
6671| [32000] Agora 'MysqlfinderAdmin.php' Remote File Include Vulnerability
6672
6673| [31517] MySQL Quick Admin 'index.php' Local File Include Vulnerability
6674
6675| [31486] MySQL Command Line Client HTML Special Characters HTML Injection Vulnerability
6676
6677| [31425] PromoteWeb MySQL 'go.php' SQL Injection Vulnerability
6678
6679| [31081] MySQL Empty Binary String Literal Remote Denial Of Service Vulnerability
6680
6681| [30835] mysql-lists Unspecified Cross Site Scripting Vulnerability
6682
6683| [30529] Keld PHP-MySQL News Script 'login.php' SQL Injection Vulnerability
6684
6685| [30383] phpwebnews-mysql Multiple SQL Injection Vulnerabilities
6686
6687| [29106] MySQL MyISAM Table Privileges Secuity Bypass Vulnerability
6688
6689| [29048] GEDCOM_to_MySQL2 Multiple Cross-Site Scripting Vulnerabilities
6690
6691| [28351] MySQL INFORMATION_SCHEMA Remote Denial Of Service Vulnerability
6692
6693| [27938] DSPAM Debian 'libdspam7-drv-mysql' Cron Job MySQL Calls Local Information Disclosure Vulnerability
6694
6695| [27202] PHP Webquest MySQL Credentials Information Disclosure Vulnerability
6696
6697| [27032] PHP MySQL Open Source Help Desk 'form.php' Code Injection Vulnerability
6698
6699| [26947] MySQL Server Unspecified Remote Arbitrary Command Execution Vulnerability
6700
6701| [26832] MySQL Server Privilege Escalation And Denial Of Service Vulnerabilities
6702
6703| [26829] aurora framework Db_mysql.LIB SQL Injection Vulnerability
6704
6705| [26765] MySQL Server RENAME TABLE System Table Overwrite Vulnerability
6706
6707| [26353] MySQL Server InnoDB CONVERT_SEARCH_MODE_TO_INNOBASE Function Denial Of Service Vulnerability
6708
6709| [26304] AdventNet EventLog Analyzer Insecure Default MySQL Password Unauthorized Access Vulnerability
6710
6711| [26156] Bacula MySQL Password Information Disclosure Vulnerability
6712
6713| [26095] Asterisk 'asterisk-addons' CDR_ADDON_MYSQL Module SQL Injection Vulnerability
6714
6715| [25017] MySQL Access Validation and Denial of Service Vulnerabilities
6716
6717| [24759] MySQLDumper Apache Access Control Authentication Bypass Vulnerability
6718
6719| [24016] MySQL Rename Table Function Access Validation Vulnerability
6720
6721| [24011] MySQL Security Invoker Privilege Escalation Vulnerability
6722
6723| [24008] MySQL Alter Table Function Information Disclosure Vulnerability
6724
6725| [23911] MySQL IF Query Handling Remote Denial Of Service Vulnerability
6726
6727| [23176] Eve-Nuke Forums MySQL.PHP Remote File Include Vulnerability
6728
6729| [22941] MySQL Commander Remote File Include Vulnerability
6730
6731| [22900] MySQL Single Row SubSelect Remote Denial Of Service Vulnerability
6732
6733| [22474] CPanel PassWDMySQL Cross-Site Scripting Vulnerability
6734
6735| [22431] MySQLNewsEngine Affichearticles.PHP3 Remote File Include Vulnerability
6736
6737| [20460] MySQLDumper SQL.PHP Cross-Site Scripting Vulnerability
6738
6739| [20222] PABugs Class.MySQL.PHP Remote File Include Vulnerability
6740
6741| [20165] ZoomStats MySQL.PHP Remote File Include Vulnerability
6742
6743| [19794] MySQL Multiupdate and Subselects Denial Of Service Vulnerability
6744
6745| [19559] MySQL Privilege Elevation and Security Bypass Vulnerabilities
6746
6747| [19279] MySQL MERGE Privilege Revoke Bypass Vulnerability
6748
6749| [19240] Banex PHP MySQL Banner Exchange Multiple Remote Vulnerabilities
6750
6751| [19032] MySQL Server Date_Format Denial Of Service Vulnerability
6752
6753| [18717] PHP/MySQL Classifieds AddAsset1.PHP Multiple HTML Injection Vulnerabilities
6754
6755| [18439] MySQL Server Str_To_Date Remote Denial Of Service Vulnerability
6756
6757| [18219] MySQL Mysql_real_escape Function SQL Injection Vulnerability
6758
6759| [17780] MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
6760
6761| [17224] Cholod MySQL Based Message Board Mb.CGI SQL Injection Vulnerability
6762
6763| [17223] Cholod MySQL Based Message Board Multiple HTML Injection Vulnerabilities
6764
6765| [17147] Woltlab Burning Board Class_DB_MySQL.PHP Cross-Site Scripting Vulnerability
6766
6767| [16850] MySQL Query Logging Bypass Vulnerability
6768
6769| [16620] PHP/MYSQL Timesheet Multiple SQL Injection Vulnerabilities
6770
6771| [16564] PAM-MySQL Code Execution And Denial Of Service Vulnerabilities
6772
6773| [16219] PHP MySQLI Error Logging Remote Format String Vulnerability
6774
6775| [16145] PHP MySQL_Connect Remote Buffer Overflow Vulnerability
6776
6777| [15852] MySQL Auction Search Module Cross-Site Scripting Vulnerability
6778
6779| [14509] MySQL User-Defined Function Buffer Overflow Vulnerability
6780
6781| [14437] MySQL Eventum Multiple SQL Injection Vulnerabilities
6782
6783| [14436] MySQL Eventum Multiple Cross-Site Scripting Vulnerabilities
6784
6785| [13913] xMySQLadmin Insecure Temporary File Creation Vulnerability
6786
6787| [13660] MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
6788
6789| [13378] MySQL MaxDB WebDAV IF Parameter Remote Buffer Overflow Vulnerability
6790
6791| [13369] MySQL MaxDB WebDAV Lock Token Remote Buffer Overflow Vulnerability
6792
6793| [13368] MySQL MaxDB HTTP GET Request Remote Buffer Overflow Vulnerability
6794
6795| [12805] MySQL MaxDB WebAgent Input Validation Multiple Remote Denial Of Service Vulnerabilities
6796
6797| [12781] MySQL AB MySQL Multiple Remote Vulnerabilities
6798
6799| [12313] MySQL MaxDB WebAgent Remote Denial of Service Vulnerabilities
6800
6801| [12277] MySQL Database MySQLAccess Local Insecure Temporary File Creation Vulnerability
6802
6803| [12265] MySQL MaxDB WebAgent WebSQL Password Parameter Remote Buffer Overflow Vulnerability
6804
6805| [12133] MySQL Eventum Multiple Input Validation Vulnerabilities
6806
6807| [11844] MySQL MaxDB WebDav Handler Overwrite Header Remote Buffer Overflow Vulnerability
6808
6809| [11843] MySQL MaxDB WAHTTP Server Remote Denial Of Service Vulnerability
6810
6811| [11435] MySQL Database Unauthorized GRANT Privilege Vulnerability
6812
6813| [11432] MySQL Remote FULLTEXT Search Denial Of Service Vulnerability
6814
6815| [11357] MySQL Multiple Local Vulnerabilities
6816
6817| [11346] MySQL MaxDB WebDBM Server Name Denial of Service Vulnerability
6818
6819| [11291] MySQL Unspecified Insecure Temporary File Creation Vulnerability
6820
6821| [11261] MySQL Bounded Parameter Statement Execution Remote Buffer Overflow Vulnerability
6822
6823| [11234] AllWebScripts MySQLGuest HTML Injection Vulnerability
6824
6825| [10986] Ben Yacoub Hatem MySQL Backup Pro Undisclosed 'getbackup()' Vulnerability
6826
6827| [10981] MySQL Mysql_real_connect Function Potential Remote Buffer Overflow Vulnerability
6828
6829| [10969] MySQL Mysqlhotcopy Script Insecure Temporary File Creation Vulnerability
6830
6831| [10655] MySQL Password Length Remote Buffer Overflow Vulnerability
6832
6833| [10654] MySQL Authentication Bypass Vulnerability
6834
6835| [10142] MySQL MYSQLD_Multi Insecure Temporary File Creation Vulnerability
6836
6837| [9976] MySQL Aborted Bug Report Insecure Temporary File Creation Vulnerability
6838
6839| [8796] MySQL Multiple Vulnerabilities
6840
6841| [8590] MySQL Password Handler Buffer Overflow Vulnerability
6842
6843| [8245] MySQL AB ODBC Driver Plain Text Password Vulnerability
6844
6845| [7887] MySQL libmysqlclient Library mysql_real_connect() Buffer Overrun Vulnerability
6846
6847| [7500] MySQL Weak Password Encryption Vulnerability
6848
6849| [7052] MySQL mysqld Privilege Escalation Vulnerability
6850
6851| [7041] MySQL Control Center Insecure Default File Permission Vulnerability
6852
6853| [6718] MySQL Double Free Heap Corruption Vulnerability
6854
6855| [6375] MySQL COM_CHANGE_USER Password Memory Corruption Vulnerability
6856
6857| [6374] MySQL libmysqlclient Library Read_One_Row Buffer Overflow Vulnerability
6858
6859| [6373] MySQL COM_CHANGE_USER Password Length Account Compromise Vulnerability
6860
6861| [6370] MySQL libmysqlclient Library Read_Rows Buffer Overflow Vulnerability
6862
6863| [6368] MySQL COM_TABLE_DUMP Memory Corruption Vulnerability
6864
6865| [5948] PHPRank MySQL Error Unauthorized Access Vulnerability
6866
6867| [5853] MySQL DataDir Parameter Local Buffer Overflow Vulnerability
6868
6869| [5513] MySQL Logging Not Enabled Weak Default Configuration Vulnerability
6870
6871| [5511] MySQL Bind Address Not Enabled Weak Default Configuration Vulnerability
6872
6873| [5503] MySQL Null Root Password Weak Default Configuration Vulnerability
6874
6875| [4409] Cyrus SASL LDAP+MySQL Authentication Patch SQL Command Execution Vulnerability
6876
6877| [4026] PHP MySQL Safe_Mode Filesystem Circumvention Vulnerability
6878
6879| [3907] Conectiva Linux MySQL World Readable Log File Vulnerability
6880
6881| [3381] WinMySQLadmin Plain Text Password Storage Vulnerability
6882
6883| [3284] Inter7 vpopmail MySQL Authentication Data Recovery Vulnerability
6884
6885| [3255] Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
6886
6887| [2522] MySQL Root Operation Symbolic Link File Overwriting Vulnerability
6888
6889| [2380] MySQL SHOW GRANTS Pasword Hash Disclosure Vulnerability
6890
6891| [2262] Mysql Local Buffer Overflow Vulnerability
6892
6893| [1850] pam_mysql Authentication Input Validation Vulnerability
6894
6895| [1826] MySQL Authentication Algorithm Vulnerability
6896
6897| [1557] PCCS Mysql Database Admin Tool Username/Password Exposure Vulnerability
6898
6899| [975] MySQL Unauthenticated Remote Access Vulnerability
6900
6901| [926] MySQL GRANT Global Password Changing Vulnerability
6902
6903|
6904
6905| SecurityTracker - http://www.securitytracker.com:
6906
6907| [1028790] MySQL Multiple Bugs Let Remote Users Deny Service and Partially Access and Modify Data
6908
6909| [1028449] MySQL Multiple Bugs Let Remote Authenticated Users Deny Service and Partially Access and Modify Data
6910
6911| [1028004] MySQL Multiple Bugs Let Remote Authenticated Users Take Full Control or Deny Service and Let Local Users Access and Modify Data
6912
6913| [1027829] MySQL Bug in UpdateXML() Lets Remote Authenticated Users Deny Service
6914
6915| [1027828] MySQL Heap Overflow May Let Remote Authenticated Users Execute Arbitrary Code
6916
6917| [1027827] MySQL Stack Overflow May Let Remote Authenticated Users Execute Arbitrary Code
6918
6919| [1027665] MySQL Multiple Bugs Let Remote Authenticated Users Access and Modify Data and Deny Service and Local Users Access Data
6920
6921| [1027263] MySQL Multiple Bugs Let Remote Authenticated Users Deny Service
6922
6923| [1027143] MySQL memcmp() Comparison Error Lets Remote Users Bypass Authentication
6924
6925| [1026934] MySQL Multiple Bugs Let Remote Users Deny Service
6926
6927| [1026896] MySQL Unspecified Flaws Have Unspecified Impact
6928
6929| [1026659] MySQL Unspecified Flaw Lets Remote Users Execute Arbitrary Code
6930
6931| [1026530] MySQL Multiple Bugs Let Local and Remote Users Partially Access and Modifiy Data and Partially Deny Service
6932
6933| [1024508] MySQL Replication Flaw Lets Remote Authenticated Users Gain Elevated Privileges
6934
6935| [1024507] MySQL Multiple Flaws Let Remote Authenticated Users Deny Service
6936
6937| [1024360] MySQL Multiple Flaws Let Remote Authenticated Users Deny Service
6938
6939| [1024160] MySQL ALTER DATABASE Processing Error Lets Remote Authenticated Users Deny Service
6940
6941| [1024033] MySQL COM_FIELD_LIST Packet Buffer Overflow Lets Remote Authenticated Users Execute Arbitrary Code
6942
6943| [1024032] MySQL Large Packet Processing Flaw in my_net_skip_rest() Lets Remote Users Deny Service
6944
6945| [1024031] MySQL COM_FIELD_LIST Validation Flaw Lets Remote Authenticated Users Gain Elevated Privileges
6946
6947| [1024004] MySQL mi_delete_table() Symlink Flaw Lets Remote Authenticated Users Delete Data and Index Files
6948
6949| [1023402] MySQL Unspecified Flaw Lets Remote Users Execute Arbitrary Code
6950
6951| [1023220] MySQL Client Fails to Check Server Certificates in Certain Cases
6952
6953| [1022812] MySQL Unspecified Buffer Overflow Lets Remote Users Execute Arbitrary Code
6954
6955| [1022533] MySQL Format String Bug in dispatch_command() Lets Remote Users Deny Service
6956
6957| [1022482] MySQL Connector/Net is Missing SSL Certificate Validation
6958
6959| [1021786] MySQL Bug in ExtractValue()/UpdateXML() in Processing XPath Expressions Lets Remote Authenticated Users Deny Service
6960
6961| [1021714] (Red Hat Issues Fix) mod_auth_mysql Input Validation Flaw Lets Remote Users Inject SQL Commands
6962
6963| [1020858] MySQL Item_bin_string::Item_bin_string() Binary Value Processing Bug Lets Remote Authenticated Users Deny Service
6964
6965| [1019995] MySQL MyISAM Options Let Local Users Overwrite Table Files
6966
6967| [1019085] MySQL Bugs Let Remote Authenticated Users Gain Elevated Privileges and Deny Service
6968
6969| [1019084] MySQL DATA DIRECTORY and INDEX DIRECTORY Options May Let Remote Authenticated Users Gain Elevated Privileges
6970
6971| [1019083] MySQL BINLOG Filename Path Bug May Let Remote Authenticated Users Gain Elevated Privileges
6972
6973| [1019060] MySQL Rename Table Bug Lets Remote Authenticated Users Modify System Table Information
6974
6975| [1018978] MySQL convert_search_mode_to_innobase() Bug Lets Remote Authenticated Users Deny Service
6976
6977| [1018824] Asterisk-Addons Input Validation Flaw in cdr_addon_mysql Lets Remote Users Inject SQL Commands
6978
6979| [1018663] MySQL Table View Access Bug Lets Remote Authenticated Users Gain Elevated Privileges
6980
6981| [1018629] MySQL Authentication Protocol Bug Lets Remote Users Deny Service
6982
6983| [1018071] MySQL ALTER TABLE Function Lets Remote Authenticated Users Obtain Potentially Sensitive Information
6984
6985| [1018070] MySQL SQL SECURITY INVOKER Routines Let Remote Authenticated Users Gain Elevated Privileges
6986
6987| [1018069] MySQL Lets Remote Authenticated Users Issue the RENAME TABLE Command
6988
6989| [1017746] MySQL Single Row Subselect Statements Let Remote Users Deny Service
6990
6991| [1016790] MySQL Replication Error Lets Local Users Deny Service
6992
6993| [1016710] MySQL Case-Sensitive Database Names May Let Users Access Restricted Databases
6994
6995| [1016709] MySQL Error in Checking suid Routine Arguments May Let Users Gain Elevated Privileges
6996
6997| [1016617] MySQL MERGE Access Control Error May Let Users Access a Restricted Table
6998
6999| [1016566] Opsware Network Automation System Discloses MySQL Password to Local Users
7000
7001| [1016216] MySQL Error in Parsing Multibyte Encoded Data in mysql_real_escape() Lets Remote Users Inject SQL Commands
7002
7003| [1016077] Apple MySQL Manager Database Initialization Bug May Let Local Users Access the Database
7004
7005| [1016017] MySQL Anonymous Login Processing May Disclose Some Memory Contents to Remote Users
7006
7007| [1016016] MySQL COM_TABLE_DUMP Processing Lets Remote Authenticated Users Execute Arbitrary Code or Obtain Information
7008
7009| [1015789] Woltlab Burning Board Input Validation Hole in 'class_db_mysql.php' Permits Cross-Site Scripting Attacks
7010
7011| [1015693] MySQL Query Bug Lets Remote Users Bypass Query Logging
7012
7013| [1015603] PAM-MySQL pam_get_item() Double Free May Let Remote Users Execute Arbitrary Code
7014
7015| [1015485] PHP mysqli Extension Error Mode Format String Flaw May Let Users Execute Arbitrary Code
7016
7017| [1014603] MySQL Eventum Input Validation Hole in 'class.auth.php' Permits SQL Injection and Other Input Validation Bugs Permit Cross-Site Scripting Attacks
7018
7019| [1014172] xMySQLadmin Lets Local Users Delete Files
7020
7021| [1013995] MySQL 'mysql_install_db' Uses Unsafe Temporary Files and May Let Local Users Gain Elevated Privilege
7022
7023| [1013994] MySQL Non-existent '--user' Error May Allow the Database to Run With Incorrect Privileges
7024
7025| [1013415] MySQL CREATE FUNCTION Lets Authenticated Users Invoke libc Functions to Execute Arbitrary Code
7026
7027| [1013414] MySQL udf_init() Path Validation Flaw Lets Authenticated Users Execute Arbitrary Libraries
7028
7029| [1013413] MySQL CREATE TEMPORARY TABLE Uses Predictable Temporary Files That May Let Users Gain Elevated Privileges
7030
7031| [1012914] MySQL 'mysqlaccess.sh' Unsafe Temporary Files May Let Local Users Gain Elevated Privileges
7032
7033| [1012893] MySQL MaxDB Buffer Overflow in websql Password Parameter Lets Remote Users Execute Arbitrary Code
7034
7035| [1012500] mysql_auth Memory Leak Has Unspecified Impact
7036
7037| [1011741] MySQL Access Control Error in Databases With Underscore Wildcard Character May Grant Unauthorized Access
7038
7039| [1011606] MySQL May Let Remote Authenticated Users Access Restricted Tables or Crash the System
7040
7041| [1011408] MySQL libmysqlclient Buffer Overflow in Executing Prepared Statements Has Unspecified Impact
7042
7043| [1011376] MySQLGuest Lack of Input Validation Lets Remote Users Conduct Cross-Site Scripting Attacks
7044
7045| [1011008] MySQL Buffer Overflow in mysql_real_connect() May Let Remote Users Execute Arbitrary Code
7046
7047| [1010979] MySQL 'mysqlhotcopy' Unsafe Temporary Files May Let Local Users Gain Elevated Privileges
7048
7049| [1010645] MySQL check_scramble_323() Zero-Length Comparison Lets Remote Users Bypass Authentication
7050
7051| [1009784] MySQL 'mysqld_multi' Temporary File Flaw Lets Local Users Overwrite Files
7052
7053| [1009554] MySQL 'mysqlbug' Temporary File Flaw Lets Local Users Overwrite Files
7054
7055| [1007979] MySQL mysql_change_user() Double Free Error Lets Remote Authenticated Users Crash mysqld
7056
7057| [1007673] MySQL acl_init() Buffer Overflow Permits Remote Authenticated Administrators to Execute Arbitrary Code
7058
7059| [1007518] DWebPro Discloses MySQL Database Password to Local Users
7060
7061| [1007312] MySQL World-Writable Configuration File May Let Local Users Gain Root Privileges
7062
7063| [1006976] MySQL Buffer Overflow in 'mysql_real_connect()' Client Function May Let Remote or Local Users Execute Arbitrary Code
7064
7065| [1005800] MySQL Overflow and Authentication Bugs May Let Remote Users Execute Code or Access Database Accounts
7066
7067| [1005345] MySQL Buffer Overflow Lets Local Users Gain System Privileges on Windows NT
7068
7069| [1004506] vBulletin PHP-based Forum Software Has Unspecified Security Flaw in the 'db_mysql.php' Module
7070
7071| [1004172] PHP-Survey Script Discloses Underlying MySQL Database Username and Password to Remote Users
7072
7073| [1003955] 3rd Party Patch for Cyrus SASL ('auxprop for mysql and ldap') Lets Remote Users Access Protected POP Mail Accounts Without Authentication
7074
7075| [1003290] Conectiva Linux MySQL Distribution May Allow Local Users to Obtain Sensitive Information
7076
7077| [1002993] PurePostPro Script Add-on for PureFTPd and MySQL Allows Remote Users to Execute SQL Commands on the Server
7078
7079| [1002485] WinMySQLadmin Database Administration Tool Discloses MySQL Password to Local Users
7080
7081| [1002324] Vpopmail Mail Server Discloses Database Password to Local Users When Installed with MySQL
7082
7083| [1001411] phpMyAdmin Administration Tool for MySQL Allows Remote Users to Execute Commands on the Server
7084
7085| [1001118] MySQL Database Allows Authorized Users to Modify Server Files to Deny Service or Obtain Additional Access
7086
7087|
7088
7089| IBM X-Force - http://xforce.iss.net:
7090
7091| [85724] Oracle MySQL Server XA Transactions denial of service
7092
7093| [85723] Oracle MySQL Server Server Replication denial of service
7094
7095| [85722] Oracle MySQL Server InnoDB denial of service
7096
7097| [85721] Oracle MySQL Server Server Privileges unspecified
7098
7099| [85720] Oracle MySQL Server Server Partition denial of service
7100
7101| [85719] Oracle MySQL Server Server Parser denial of service
7102
7103| [85718] Oracle MySQL Server Server Options denial of service
7104
7105| [85717] Oracle MySQL Server Server Options denial of service
7106
7107| [85716] Oracle MySQL Server Server Optimizer denial of service
7108
7109| [85715] Oracle MySQL Server Server Optimizer denial of service
7110
7111| [85714] Oracle MySQL Server Prepared Statements denial of service
7112
7113| [85713] Oracle MySQL Server InnoDB denial of service
7114
7115| [85712] Oracle MySQL Server Full Text Search denial of service
7116
7117| [85711] Oracle MySQL Server Data Manipulation Language denial of service
7118
7119| [85710] Oracle MySQL Server Data Manipulation Language denial of service
7120
7121| [85709] Oracle MySQL Server Audit Log unspecified
7122
7123| [85708] Oracle MySQL Server MemCached unspecified
7124
7125| [84846] Debian mysql-server package information disclosure
7126
7127| [84375] Wireshark MySQL dissector denial of service
7128
7129| [83554] Oracle MySQL Server Server Partition denial of service
7130
7131| [83553] Oracle MySQL Server Server Locking denial of service
7132
7133| [83552] Oracle MySQL Server Server Install unspecified
7134
7135| [83551] Oracle MySQL Server Server Types denial of service
7136
7137| [83550] Oracle MySQL Server Server Privileges unspecified
7138
7139| [83549] Oracle MySQL Server InnoDB denial of service
7140
7141| [83548] Oracle MySQL Server InnoDB denial of service
7142
7143| [83547] Oracle MySQL Server Data Manipulation Language denial of service
7144
7145| [83546] Oracle MySQL Server Stored Procedure denial of service
7146
7147| [83545] Oracle MySQL Server Server Replication denial of service
7148
7149| [83544] Oracle MySQL Server Server Partition denial of service
7150
7151| [83543] Oracle MySQL Server Server Optimizer denial of service
7152
7153| [83542] Oracle MySQL Server InnoDB denial of service
7154
7155| [83541] Oracle MySQL Server Information Schema denial of service
7156
7157| [83540] Oracle MySQL Server Data Manipulation Language denial of service
7158
7159| [83539] Oracle MySQL Server Data Manipulation Language denial of service
7160
7161| [83538] Oracle MySQL Server Server Optimizer unspecified
7162
7163| [83537] Oracle MySQL Server MemCached denial of service
7164
7165| [83536] Oracle MySQL Server Server Privileges unspecified
7166
7167| [83535] Oracle MySQL Server Server Privileges unspecified
7168
7169| [83534] Oracle MySQL Server Server unspecified
7170
7171| [83533] Oracle MySQL Server Information Schema unspecified
7172
7173| [83532] Oracle MySQL Server Server Locking unspecified
7174
7175| [83531] Oracle MySQL Server Data Manipulation Language denial of service
7176
7177| [83388] MySQL administrative login attempt detected
7178
7179| [82963] Mambo MySQL database information disclosure
7180
7181| [82946] Oracle MySQL buffer overflow
7182
7183| [82945] Oracle MySQL buffer overflow
7184
7185| [82895] Oracle MySQL and MariaDB geometry queries denial of service
7186
7187| [81577] MySQL2JSON extension for TYPO3 unspecified SQL injection
7188
7189| [81325] Oracle MySQL Server Server Privileges denial of service
7190
7191| [81324] Oracle MySQL Server Server Partition denial of service
7192
7193| [81323] Oracle MySQL Server Server Optimizer denial of service
7194
7195| [81322] Oracle MySQL Server Server Optimizer denial of service
7196
7197| [81321] Oracle MySQL Server Server denial of service
7198
7199| [81320] Oracle MySQL Server MyISAM denial of service
7200
7201| [81319] Oracle MySQL Server InnoDB denial of service
7202
7203| [81318] Oracle MySQL Server InnoDB denial of service
7204
7205| [81317] Oracle MySQL Server Server Locking denial of service
7206
7207| [81316] Oracle MySQL Server Server denial of service
7208
7209| [81315] Oracle MySQL Server Server Replication unspecified
7210
7211| [81314] Oracle MySQL Server Server Replication unspecified
7212
7213| [81313] Oracle MySQL Server Stored Procedure denial of service
7214
7215| [81312] Oracle MySQL Server Server Optimizer denial of service
7216
7217| [81311] Oracle MySQL Server Information Schema denial of service
7218
7219| [81310] Oracle MySQL Server GIS Extension denial of service
7220
7221| [80790] Oracle MySQL yaSSL buffer overflow
7222
7223| [80553] Oracle MySQL and MariaDB salt security bypass
7224
7225| [80443] Oracle MySQL Server unspecified code execution
7226
7227| [80442] Oracle MySQL Server acl_get() buffer overflow
7228
7229| [80440] Oracle MySQL Server table buffer overflow
7230
7231| [80435] Oracle MySQL Server database privilege escalation
7232
7233| [80434] Oracle MySQL Server COM_BINLOG_DUMP denial of service
7234
7235| [80433] Oracle MySQL Server Stuxnet privilege escalation
7236
7237| [80432] Oracle MySQL Server authentication information disclosure
7238
7239| [79394] Oracle MySQL Server Server Installation information disclosure
7240
7241| [79393] Oracle MySQL Server Server Replication denial of service
7242
7243| [79392] Oracle MySQL Server Server Full Text Search denial of service
7244
7245| [79391] Oracle MySQL Server Server denial of service
7246
7247| [79390] Oracle MySQL Server Client information disclosure
7248
7249| [79389] Oracle MySQL Server Server Optimizer denial of service
7250
7251| [79388] Oracle MySQL Server Server Optimizer denial of service
7252
7253| [79387] Oracle MySQL Server Server denial of service
7254
7255| [79386] Oracle MySQL Server InnoDB Plugin denial of service
7256
7257| [79385] Oracle MySQL Server InnoDB denial of service
7258
7259| [79384] Oracle MySQL Server Client unspecified
7260
7261| [79383] Oracle MySQL Server Server denial of service
7262
7263| [79382] Oracle MySQL Server Protocol unspecified
7264
7265| [79381] Oracle MySQL Server Information Schema unspecified
7266
7267| [78954] SilverStripe MySQLDatabase.php information disclosure
7268
7269| [78948] MySQL MyISAM table symlink
7270
7271| [77865] MySQL unknown vuln
7272
7273| [77864] MySQL sort order denial of service
7274
7275| [77768] MySQLDumper refresh_dblist.php information disclosure
7276
7277| [77177] MySQL Squid Access Report unspecified cross-site scripting
7278
7279| [77065] Oracle MySQL Server Optimizer denial of service
7280
7281| [77064] Oracle MySQL Server Optimizer denial of service
7282
7283| [77063] Oracle MySQL Server denial of service
7284
7285| [77062] Oracle MySQL InnoDB denial of service
7286
7287| [77061] Oracle MySQL GIS Extension denial of service
7288
7289| [77060] Oracle MySQL Server Optimizer denial of service
7290
7291| [76189] MySQL unspecified error
7292
7293| [76188] MySQL attempts security bypass
7294
7295| [75287] MySQLDumper restore.php information disclosure
7296
7297| [75286] MySQLDumper filemanagement.php directory traversal
7298
7299| [75285] MySQLDumper main.php cross-site request forgery
7300
7301| [75284] MySQLDumper install.php cross-site scripting
7302
7303| [75283] MySQLDumper install.php file include
7304
7305| [75282] MySQLDumper menu.php code execution
7306
7307| [75022] Oracle MySQL Server Server Optimizer denial of service
7308
7309| [75021] Oracle MySQL Server Server Optimizer denial of service
7310
7311| [75020] Oracle MySQL Server Server DML denial of service
7312
7313| [75019] Oracle MySQL Server Partition denial of service
7314
7315| [75018] Oracle MySQL Server MyISAM denial of service
7316
7317| [75017] Oracle MySQL Server Server Optimizer denial of service
7318
7319| [74672] Oracle MySQL Server multiple unspecified
7320
7321| [73092] MySQL unspecified code execution
7322
7323| [72540] Oracle MySQL Server denial of service
7324
7325| [72539] Oracle MySQL Server unspecified
7326
7327| [72538] Oracle MySQL Server denial of service
7328
7329| [72537] Oracle MySQL Server denial of service
7330
7331| [72536] Oracle MySQL Server unspecified
7332
7333| [72535] Oracle MySQL Server denial of service
7334
7335| [72534] Oracle MySQL Server denial of service
7336
7337| [72533] Oracle MySQL Server denial of service
7338
7339| [72532] Oracle MySQL Server denial of service
7340
7341| [72531] Oracle MySQL Server denial of service
7342
7343| [72530] Oracle MySQL Server denial of service
7344
7345| [72529] Oracle MySQL Server denial of service
7346
7347| [72528] Oracle MySQL Server denial of service
7348
7349| [72527] Oracle MySQL Server denial of service
7350
7351| [72526] Oracle MySQL Server denial of service
7352
7353| [72525] Oracle MySQL Server information disclosure
7354
7355| [72524] Oracle MySQL Server denial of service
7356
7357| [72523] Oracle MySQL Server denial of service
7358
7359| [72522] Oracle MySQL Server denial of service
7360
7361| [72521] Oracle MySQL Server denial of service
7362
7363| [72520] Oracle MySQL Server denial of service
7364
7365| [72519] Oracle MySQL Server denial of service
7366
7367| [72518] Oracle MySQL Server unspecified
7368
7369| [72517] Oracle MySQL Server unspecified
7370
7371| [72516] Oracle MySQL Server unspecified
7372
7373| [72515] Oracle MySQL Server denial of service
7374
7375| [72514] Oracle MySQL Server unspecified
7376
7377| [71965] MySQL port denial of service
7378
7379| [70680] DBD::mysqlPP unspecified SQL injection
7380
7381| [70370] TaskFreak! multi-mysql unspecified path disclosure
7382
7383| [68799] mod_authnz_external module for Apache mysql-auth.pl SQL injection
7384
7385| [68294] MySQLDriverCS statement.cs sql injection
7386
7387| [68175] Prosody MySQL denial of service
7388
7389| [67539] Zend Framework MySQL PDO security bypass
7390
7391| [67254] DirectAdmin MySQL information disclosure
7392
7393| [66567] Xoops mysql.sql information disclosure
7394
7395| [65871] PyWebDAV MySQLAuthHandler class SQL injection
7396
7397| [65543] MySQL Select Arbitrary data into a File
7398
7399| [65529] MySQL Eventum full_name field cross-site scripting
7400
7401| [65380] Oracle MySQL Eventum forgot_password.php cross-site scripting
7402
7403| [65379] Oracle MySQL Eventum list.php cross-site scripting
7404
7405| [65266] Accellion File Transfer Appliance MySQL default password
7406
7407| [64878] MySQL Geometry denial of service
7408
7409| [64877] MySQL EXPLAIN EXTENDED denial of service
7410
7411| [64876] MySQL prepared statement denial of service
7412
7413| [64845] MySQL extreme-value denial of service
7414
7415| [64844] MySQL Gis_line_string::init_from_wkb denial of service
7416
7417| [64843] MySQL user-variable denial of service
7418
7419| [64842] MySQL view preparation denial of service
7420
7421| [64841] MySQL prepared statement denial of service
7422
7423| [64840] MySQL LONGBLOB denial of service
7424
7425| [64839] MySQL invocations denial of service
7426
7427| [64838] MySQL Gis_line_string::init_from_wkb denial of service
7428
7429| [64689] MySQL dict0crea.c denial of service
7430
7431| [64688] MySQL SET column denial of service
7432
7433| [64687] MySQL BINLOG command denial of service
7434
7435| [64686] MySQL InnoDB denial of service
7436
7437| [64685] MySQL HANDLER interface denial of service
7438
7439| [64684] MySQL Item_singlerow_subselect::store denial of service
7440
7441| [64683] MySQL OK packet denial of service
7442
7443| [63518] MySQL Query Browser GUI Tools information disclosure
7444
7445| [63517] MySQL Administrator GUI Tools information disclosure
7446
7447| [62272] MySQL PolyFromWKB() denial of service
7448
7449| [62269] MySQL LIKE predicates denial of service
7450
7451| [62268] MySQL joins denial of service
7452
7453| [62267] MySQL GREATEST() or LEAST() denial of service
7454
7455| [62266] MySQL GROUP_CONCAT() denial of service
7456
7457| [62265] MySQL expression values denial of service
7458
7459| [62264] MySQL temporary table denial of service
7460
7461| [62263] MySQL LEAST() or GREATEST() denial of service
7462
7463| [62262] MySQL replication privilege escalation
7464
7465| [61739] MySQL WITH ROLLUP denial of service
7466
7467| [61343] MySQL LOAD DATA INFILE denial of service
7468
7469| [61342] MySQL EXPLAIN denial of service
7470
7471| [61341] MySQL HANDLER denial of service
7472
7473| [61340] MySQL BINLOG denial of service
7474
7475| [61339] MySQL IN() or CASE denial of service
7476
7477| [61338] MySQL SET denial of service
7478
7479| [61337] MySQL DDL denial of service
7480
7481| [61318] PHP mysqlnd_wireprotocol.c buffer overflow
7482
7483| [61317] PHP php_mysqlnd_read_error_from_line buffer overflow
7484
7485| [61316] PHP php_mysqlnd_auth_write buffer overflow
7486
7487| [61274] MySQL TEMPORARY InnoDB denial of service
7488
7489| [59905] MySQL ALTER DATABASE denial of service
7490
7491| [59841] CMySQLite updateUser.php cross-site request forgery
7492
7493| [59112] MySQL Enterprise Monitor unspecified cross-site request forgery
7494
7495| [59075] PHP php_mysqlnd_auth_write() buffer overflow
7496
7497| [59074] PHP php_mysqlnd_read_error_from_line() buffer overflow
7498
7499| [59073] PHP php_mysqlnd_rset_header_read() buffer overflow
7500
7501| [59072] PHP php_mysqlnd_ok_read() information disclosure
7502
7503| [58842] MySQL DROP TABLE file deletion
7504
7505| [58676] Template Shares MySQL information disclosure
7506
7507| [58531] MySQL COM_FIELD_LIST buffer overflow
7508
7509| [58530] MySQL packet denial of service
7510
7511| [58529] MySQL COM_FIELD_LIST security bypass
7512
7513| [58311] ClanSphere the captcha generator and MySQL driver SQL injection
7514
7515| [57925] MySQL UNINSTALL PLUGIN security bypass
7516
7517| [57006] Quicksilver Forums mysqldump information disclosure
7518
7519| [56800] Employee Timeclock Software mysqldump information disclosure
7520
7521| [56200] Flex MySQL Connector ActionScript SQL injection
7522
7523| [55877] MySQL yaSSL buffer overflow
7524
7525| [55622] kiddog_mysqldumper extension for TYPO3 information disclosure
7526
7527| [55416] MySQL unspecified buffer overflow
7528
7529| [55382] Ublog UblogMySQL.sql information disclosure
7530
7531| [55251] PHP-MySQL-Quiz editquiz.php SQL injection
7532
7533| [54597] MySQL sql_table.cc security bypass
7534
7535| [54596] MySQL mysqld denial of service
7536
7537| [54365] MySQL OpenSSL security bypass
7538
7539| [54364] MySQL MyISAM table symlink
7540
7541| [53950] The mysql-ocaml mysql_real_escape_string weak security
7542
7543| [52978] Zmanda Recovery Manager for MySQL mysqlhotcopy privilege escalation
7544
7545| [52977] Zmanda Recovery Manager for MySQL socket-server.pl command execution
7546
7547| [52660] iScouter PHP Web Portal MySQL Password Retrieval
7548
7549| [52220] aa33code mysql.inc information disclosure
7550
7551| [52122] MySQL Connector/J unicode SQL injection
7552
7553| [51614] MySQL dispatch_command() denial of service
7554
7555| [51406] MySQL Connector/NET SSL spoofing
7556
7557| [49202] MySQL UDF command execution
7558
7559| [49050] MySQL XPath denial of service
7560
7561| [48919] Cisco Application Networking Manager MySQL default account password
7562
7563| [48163] libapache2-mod-auth-mysql module for Debian multibyte encoding SQL injection
7564
7565| [47544] MySQL Calendar index.php SQL injection
7566
7567| [47476] MySQL Calendar index.php nodstrumCalendarV2 security bypass
7568
7569| [45649] MySQL MyISAM symlink security bypass
7570
7571| [45648] MySQL MyISAM symlinks security bypass
7572
7573| [45607] MySQL Quick Admin actions.php file include
7574
7575| [45606] MySQL Quick Admin index.php file include
7576
7577| [45590] MySQL command-line client cross-site scripting
7578
7579| [45436] PromoteWeb MySQL go.php SQL injection
7580
7581| [45042] MySQL empty bit-string literal denial of service
7582
7583| [44662] mysql-lists unspecified cross-site scripting
7584
7585| [42267] MySQL MyISAM security bypass
7586
7587| [42211] GEDCOM_to_MySQL2 index.php, info.php and prenom.php cross-site scripting
7588
7589| [42014] miniBB setup_mysql.php and setup_options.php SQL injection
7590
7591| [40920] MySQL sql_select.cc denial of service
7592
7593| [40734] MySQL Server BINLOG privilege escalation
7594
7595| [40350] MySQL password information disclosure
7596
7597| [39415] Debian GNU/Linux libdspam7-drv-mysql cron job password disclosure
7598
7599| [39402] PHP LOCAL INFILE and MySQL extension security bypass
7600
7601| [38999] aurora framework db_mysql.lib SQL injection
7602
7603| [38990] MySQL federated engine denial of service
7604
7605| [38989] MySQL DEFINER value privilege escalation
7606
7607| [38988] MySQL DATA DIRECTORY and INDEX DIRECTORY privilege escalation
7608
7609| [38964] MySQL RENAME TABLE symlink
7610
7611| [38733] ManageEngine EventLog Analyzer MySQL default password
7612
7613| [38284] MySQL ha_innodb.cc convert_search_mode_to_innobase() denial of service
7614
7615| [38189] MySQL default root password
7616
7617| [37235] Asterisk-Addons cdr_addon_mysql module SQL injection
7618
7619| [37099] RHSA update for MySQL case sensistive database name privilege escalation not installed
7620
7621| [36555] PHP MySQL extension multiple functions security bypass
7622
7623| [35960] MySQL view privilege escalation
7624
7625| [35959] MySQL CREATE TABLE LIKE information disclosure
7626
7627| [35958] MySQL connection protocol denial of service
7628
7629| [35291] MySQLDumper main.php security bypass
7630
7631| [34811] MySQL udf_init and mysql_create_function command execution
7632
7633| [34809] MySQL mysql_update privilege escalation
7634
7635| [34349] MySQL ALTER information disclosure
7636
7637| [34348] MySQL mysql_change_db privilege escalation
7638
7639| [34347] MySQL RENAME TABLE weak security
7640
7641| [34232] MySQL IF clause denial of service
7642
7643| [33388] Advanced Website Creator (AWC) mysql_escape_string SQL injection
7644
7645| [33285] Eve-Nuke mysql.php file include
7646
7647| [32957] MySQL Commander dbopen.php file include
7648
7649| [32933] cPanel load_language.php and mysqlconfig.php file include
7650
7651| [32911] MySQL filesort function denial of service
7652
7653| [32462] cPanel passwdmysql cross-site scripting
7654
7655| [32288] RHSA-2006:0544 updates for mysql not installed
7656
7657| [32266] MySQLNewsEngine affichearticles.php3 file include
7658
7659| [31244] The Address Book MySQL export.php password information disclosure
7660
7661| [31037] Php/Mysql Site Builder (PHPBuilder) htm2php.php directory traversal
7662
7663| [30760] BTSaveMySql URL file disclosure
7664
7665| [30191] StoryStream mysql.php and mysqli.php file include
7666
7667| [30085] MySQL MS-DOS device name denial of service
7668
7669| [30031] Agora MysqlfinderAdmin.php file include
7670
7671| [29438] MySQLDumper mysqldumper_path/sql.php cross-site scripting
7672
7673| [29179] paBugs class.mysql.php file include
7674
7675| [29120] ZoomStats MySQL file include
7676
7677| [28448] MySQL case sensitive database name privilege escalation
7678
7679| [28442] MySQL GRANT EXECUTE privilege escalation
7680
7681| [28387] FunkBoard admin/mysql_install.php and admin/pg_install.php unauthorized access
7682
7683| [28202] MySQL multiupdate subselect query denial of service
7684
7685| [28180] MySQL MERGE table security bypass
7686
7687| [28176] PHP MySQL Banner Exchange lib.inc information disclosure
7688
7689| [27995] Opsware Network Automation System MySQL plaintext password
7690
7691| [27904] MySQL date_format() format string
7692
7693| [27635] MySQL Instance Manager denial of service
7694
7695| [27212] MySQL SELECT str_to_date denial of service
7696
7697| [26875] MySQL ASCII escaping SQL injection
7698
7699| [26420] Apple Mac OS X MySQL Manager blank password
7700
7701| [26236] MySQL login packet information disclosure
7702
7703| [26232] MySQL COM_TABLE_DUMP buffer overflow
7704
7705| [26228] MySQL sql_parce.cc information disclosure
7706
7707| [26042] MySQL running
7708
7709| [25313] WoltLab Burning Board class_db_mysql.php cross-site scripting
7710
7711| [24966] MySQL mysql_real_query logging bypass
7712
7713| [24653] PAM-MySQL logging function denial of service
7714
7715| [24652] PAM-MySQL authentication double free code execution
7716
7717| [24567] PHP/MYSQL Timesheet index.php and changehrs.php SQL injection
7718
7719| [24095] PHP ext/mysqli exception handling format string
7720
7721| [23990] PHP mysql_connect() buffer overflow
7722
7723| [23596] MySQL Auction search module could allow cross-site scripting
7724
7725| [22642] RHSA-2005:334 updates for mysql not installed
7726
7727| [21757] MySQL UDF library functions command execution
7728
7729| [21756] MySQL LoadLibraryEx function denial of service
7730
7731| [21738] MySQL UDF mysql_create_function function directory traversal
7732
7733| [21737] MySQL user defined function buffer overflow
7734
7735| [21640] MySQL Eventum multiple class SQL injection
7736
7737| [21638] MySQL Eventum multiple scripts cross-site scripting
7738
7739| [20984] xmysqladmin temporary file symlink
7740
7741| [20656] MySQL mysql_install_db script symlink
7742
7743| [20333] Plans MySQL password information disclosure
7744
7745| [19659] MySQL CREATE TEMPORARY TABLE command creates insecure files
7746
7747| [19658] MySQL udf_init function gain access
7748
7749| [19576] auraCMS mysql_fetch_row function path disclosure
7750
7751| [18922] MySQL mysqlaccess script symlink attack
7752
7753| [18824] MySQL UDF root privileges
7754
7755| [18464] mysql_auth unspecified vulnerability
7756
7757| [18449] Sugar Sales plaintext MySQL password
7758
7759| [17783] MySQL underscore allows elevated privileges
7760
7761| [17768] MySQL MATCH ... AGAINST SQL statement denial of service
7762
7763| [17667] MySQL UNION change denial of service
7764
7765| [17666] MySQL ALTER TABLE RENAME bypass restriction
7766
7767| [17493] MySQL libmysqlclient bulk inserts buffer overflow
7768
7769| [17462] MySQLGuest AWSguest.php script cross-site scripting
7770
7771| [17047] MySQL mysql_real_connect buffer overflow
7772
7773| [17030] MySQL mysqlhotcopy insecure temporary file
7774
7775| [16612] MySQL my_rnd buffer overflow
7776
7777| [16604] MySQL check_scramble_323 function allows unauthorized access
7778
7779| [15883] MySQL mysqld_multi script symlink attack
7780
7781| [15617] MySQL mysqlbug script symlink attack
7782
7783| [15417] Confixx db_mysql_loeschen2.php SQL injection
7784
7785| [15280] Proofpoint Protection Server MySQL allows unauthorized access
7786
7787| [13404] HP Servicecontrol Manager multiple vulnerabilities in MySQL could allow execution of code
7788
7789| [13153] MySQL long password buffer overflow
7790
7791| [12689] MySQL AB ODBC Driver stores ODBC passwords and usernames in plain text
7792
7793| [12540] Teapop PostSQL and MySQL modules SQL injection
7794
7795| [12337] MySQL mysql_real_connect function buffer overflow
7796
7797| [11510] MySQL datadir/my.cnf modification could allow root privileges
7798
7799| [11493] mysqlcc configuration and connection files are world writable
7800
7801| [11340] SuckBot mod_mysql_logger denial of service
7802
7803| [11199] MySQL mysql_change_user() double-free memory pointer denial of service
7804
7805| [10850] MySQL libmysql client read_one_row buffer overflow
7806
7807| [10849] MySQL libmysql client read_rows buffer overflow
7808
7809| [10848] MySQL COM_CHANGE_USER password buffer overflow
7810
7811| [10847] MySQL COM_CHANGE_USER command password authentication bypass
7812
7813| [10846] MySQL COM_TABLE_DUMP unsigned integer denial of service
7814
7815| [10483] Bugzilla stores passwords in plain text in the MySQL database
7816
7817| [10455] gBook MySQL could allow administrative access
7818
7819| [10243] MySQL my.ini "
7820
7821| [9996] MySQL SHOW GRANTS command discloses adminstrator`s encrypted password
7822
7823| [9909] MySQL logging disabled by default on Windows
7824
7825| [9908] MySQL binding to the loopback adapter is disabled
7826
7827| [9902] MySQL default root password could allow unauthorized access
7828
7829| [8748] Cyrus SASL LDAP+MySQL patch allows user unauthorized POP access
7830
7831| [8105] PHP MySQL client library allows an attacker to bypass safe_mode restrictions
7832
7833| [7923] Conectiva Linux MySQL /var/log/mysql file has insecure permissions
7834
7835| [7206] WinMySQLadmin stores MySQL password in plain text
7836
7837| [6617] MySQL "
7838
7839| [6419] MySQL drop database command buffer overflow
7840
7841| [6418] MySQL libmysqlclient.so buffer overflow
7842
7843| [5969] MySQL select buffer overflow
7844
7845| [5447] pam_mysql authentication input
7846
7847| [5409] MySQL authentication algorithm obtain password hash
7848
7849| [5057] PCCS MySQL Database Admin Tool could reveal username and password
7850
7851| [4228] MySQL unauthenticated remote access
7852
7853| [3849] MySQL default test account could allow any user to connect to the database
7854
7855| [1568] MySQL creates readable log files
7856
7857|
7858
7859| Exploit-DB - http://www.exploit-db.com:
7860
7861| [5913] MyBlog: PHP and MySQL Blog/CMS software (SQL/XSS) Vulnerabilities
7862
7863| [21266] PHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability (3)
7864
7865| [21265] PHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability (2)
7866
7867| [21264] PHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability (1)
7868
7869| [8037] ProFTPd with mod_mysql Authentication Bypass Vulnerability
7870
7871| [6641] MySQL Quick Admin <= 1.5.5 (COOKIE) Local File Inclusion Vulnerability
7872
7873|
7874
7875| OpenVAS (Nessus) - http://www.openvas.org:
7876
7877| [902675] MySQLDumper Multiple Vulnerabilities
7878
7879| [881549] CentOS Update for mysql CESA-2012:1551 centos6
7880
7881| [881538] CentOS Update for mysql CESA-2012:1462 centos6
7882
7883| [881225] CentOS Update for mysql CESA-2012:0105 centos6
7884
7885| [881185] CentOS Update for mysql CESA-2012:0127 centos5
7886
7887| [881061] CentOS Update for mysql CESA-2012:0874 centos6
7888
7889| [880760] CentOS Update for mysql CESA-2009:1289 centos5 i386
7890
7891| [880613] CentOS Update for mysql CESA-2010:0109 centos5 i386
7892
7893| [880577] CentOS Update for mysql CESA-2010:0442 centos5 i386
7894
7895| [880452] CentOS Update for mysql CESA-2010:0824 centos4 i386
7896
7897| [880366] CentOS Update for mysql CESA-2010:0110 centos4 i386
7898
7899| [880329] CentOS Update for mysql CESA-2007:1155 centos4 x86_64
7900
7901| [880324] CentOS Update for mysql CESA-2007:1155 centos4 i386
7902
7903| [870870] RedHat Update for mysql RHSA-2012:1551-01
7904
7905| [870861] RedHat Update for mysql RHSA-2012:1462-01
7906
7907| [870778] RedHat Update for mysql RHSA-2012:0874-04
7908
7909| [870736] RedHat Update for mysql RHSA-2011:0164-01
7910
7911| [870647] RedHat Update for mysql RHSA-2012:0105-01
7912
7913| [870547] RedHat Update for mysql RHSA-2012:0127-01
7914
7915| [870357] RedHat Update for mysql RHSA-2010:0824-01
7916
7917| [870356] RedHat Update for mysql RHSA-2010:0825-01
7918
7919| [870272] RedHat Update for mysql RHSA-2010:0442-01
7920
7921| [870218] RedHat Update for mysql RHSA-2010:0110-01
7922
7923| [870216] RedHat Update for mysql RHSA-2010:0109-01
7924
7925| [870195] RedHat Update for mysql RHSA-2007:1155-01
7926
7927| [870069] RedHat Update for mysql RHSA-2008:0364-01
7928
7929| [870033] RedHat Update for mysql RHSA-2008:0768-01
7930
7931| [864951] Fedora Update for mysql FEDORA-2012-19823
7932
7933| [864945] Fedora Update for mysql FEDORA-2012-19833
7934
7935| [864504] Fedora Update for mysql FEDORA-2012-9324
7936
7937| [864474] Fedora Update for mysql FEDORA-2012-9308
7938
7939| [863910] Fedora Update for mysql FEDORA-2012-0972
7940
7941| [863725] Fedora Update for mysql FEDORA-2012-0987
7942
7943| [862844] Fedora Update for mod_auth_mysql FEDORA-2011-0100
7944
7945| [862840] Fedora Update for mod_auth_mysql FEDORA-2011-0114
7946
7947| [862676] Fedora Update for mysql FEDORA-2010-15147
7948
7949| [862444] Fedora Update for mysql FEDORA-2010-15166
7950
7951| [862300] Fedora Update for mysql FEDORA-2010-11126
7952
7953| [862290] Fedora Update for mysql FEDORA-2010-11135
7954
7955| [862149] Fedora Update for mysql FEDORA-2010-9053
7956
7957| [862148] Fedora Update for mysql FEDORA-2010-9061
7958
7959| [862136] Fedora Update for mysql FEDORA-2010-9016
7960
7961| [861948] Fedora Update for mysql FEDORA-2010-7355
7962
7963| [861936] Fedora Update for mysql FEDORA-2010-7414
7964
7965| [861707] Fedora Update for mysql FEDORA-2010-1300
7966
7967| [861651] Fedora Update for mysql FEDORA-2010-1348
7968
7969| [861544] Fedora Update for php-pear-MDB2-Driver-mysql FEDORA-2007-3369
7970
7971| [861392] Fedora Update for mysql FEDORA-2007-4471
7972
7973| [861180] Fedora Update for php-pear-MDB2-Driver-mysqli FEDORA-2007-3369
7974
7975| [861162] Fedora Update for php-pear-MDB2-Driver-mysql FEDORA-2007-3376
7976
7977| [861108] Fedora Update for php-pear-MDB2-Driver-mysqli FEDORA-2007-3376
7978
7979| [861033] Fedora Update for mysql FEDORA-2007-4465
7980
7981| [855481] Solaris Update for mysql 120292-02
7982
7983| [855333] Solaris Update for mysql 120293-02
7984
7985| [850182] SuSE Update for mysql openSUSE-SU-2012:0860-1 (mysql)
7986
7987| [841248] Ubuntu Update for mysql-5.5 USN-1658-1
7988
7989| [841207] Ubuntu Update for mysql-5.5 USN-1621-1
7990
7991| [841039] Ubuntu Update for mysql-5.5 USN-1467-1
7992
7993| [840989] Ubuntu Update for mysql-5.1 USN-1427-1
7994
7995| [840944] Ubuntu Update for mysql-5.1 USN-1397-1
7996
7997| [840533] Ubuntu Update for MySQL vulnerabilities USN-1017-1
7998
7999| [840442] Ubuntu Update for MySQL vulnerabilities USN-950-1
8000
8001| [840384] Ubuntu Update for MySQL vulnerabilities USN-897-1
8002
8003| [840292] Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-671-1
8004
8005| [840240] Ubuntu Update for mysql-dfsg-5.0 regression USN-588-2
8006
8007| [840219] Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-588-1
8008
8009| [840106] Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-559-1
8010
8011| [840042] Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-528-1
8012
8013| [840012] Ubuntu Update for mysql-dfsg-5.0 vulnerability USN-440-1
8014
8015| [835096] HP-UX Update for on HP 9000 Servers Running MySQL HPSBUX00287
8016
8017| [831755] Mandriva Update for mysql MDVSA-2012:178 (mysql)
8018
8019| [831684] Mandriva Update for mysql MDVA-2012:049 (mysql)
8020
8021| [831547] Mandriva Update for mysql MDVA-2012:022 (mysql)
8022
8023| [831532] Mandriva Update for mysql MDVA-2012:005 (mysql)
8024
8025| [831519] Mandriva Update for mysql MDVA-2011:099 (mysql)
8026
8027| [831425] Mandriva Update for mysql MDVA-2011:025 (mysql)
8028
8029| [831327] Mandriva Update for mysql MDVA-2011:005 (mysql)
8030
8031| [831315] Mandriva Update for mysql MDVSA-2011:012 (mysql)
8032
8033| [831295] Mandriva Update for mysql MDVA-2010:240 (mysql)
8034
8035| [831244] Mandriva Update for mysql MDVSA-2010:155-1 (mysql)
8036
8037| [831243] Mandriva Update for mysql MDVSA-2010:222 (mysql)
8038
8039| [831237] Mandriva Update for mysql MDVSA-2010:223 (mysql)
8040
8041| [831202] Mandriva Update for mysql MDVA-2010:210 (mysql)
8042
8043| [831134] Mandriva Update for mysql MDVSA-2010:155 (mysql)
8044
8045| [831049] Mandriva Update for mysql MDVSA-2010:107 (mysql)
8046
8047| [831048] Mandriva Update for mysql MDVSA-2010:101 (mysql)
8048
8049| [831034] Mandriva Update for mysql MDVA-2010:146 (mysql)
8050
8051| [831033] Mandriva Update for mysql MDVSA-2010:093 (mysql)
8052
8053| [830902] Mandriva Update for mysql MDVSA-2010:044 (mysql)
8054
8055| [830821] Mandriva Update for mysql MDVSA-2010:011 (mysql)
8056
8057| [830806] Mandriva Update for mysql MDVSA-2010:012 (mysql)
8058
8059| [830772] Mandriva Update for mysql MDVSA-2008:150 (mysql)
8060
8061| [830664] Mandriva Update for mysql MDVA-2008:018 (mysql)
8062
8063| [830659] Mandriva Update for mysql MDVSA-2008:017 (mysql)
8064
8065| [830513] Mandriva Update for mysql MDVSA-2008:028 (mysql)
8066
8067| [830421] Mandriva Update for mysql MDVSA-2008:149 (mysql)
8068
8069| [830297] Mandriva Update for MySQL MDKSA-2007:177 (MySQL)
8070
8071| [830223] Mandriva Update for perl-DBD-mysql MDKA-2007:066 (perl-DBD-mysql)
8072
8073| [830063] Mandriva Update for MySQL MDKSA-2007:139 (MySQL)
8074
8075| [830032] Mandriva Update for MySQL MDKSA-2007:243 (MySQL)
8076
8077| [801593] Oracle MySQL Eventum Multiple Cross Site Scripting Vulnerabilities
8078
8079| [801205] MySQL Connector/Net SSL Certificate Validation Security Bypass Vulnerability
8080
8081| [103051] PHP MySQLi Extension 'set_magic_quotes_runtime' Function Security-Bypass Weakness
8082
8083| [100662] PHP Mysqlnd Extension Information Disclosure and Multiple Buffer Overflow Vulnerabilities
8084
8085| [71475] Debian Security Advisory DSA 2496-1 (mysql-5.1)
8086
8087| [71233] Debian Security Advisory DSA 2429-1 (mysql-5.1)
8088
8089| [70803] Gentoo Security Advisory GLSA 201201-02 (MySQL)
8090
8091| [70586] FreeBSD Ports: proftpd, proftpd-mysql
8092
8093| [67541] Debian Security Advisory DSA 2057-1 (mysql-dfsg-5.0)
8094
8095| [66577] Fedora Core 11 FEDORA-2009-13504 (mysql)
8096
8097| [66573] Fedora Core 12 FEDORA-2009-13466 (mysql)
8098
8099| [66553] Mandriva Security Advisory MDVSA-2009:189-1 (apache-mod_auth_mysql)
8100
8101| [66508] Fedora Core 10 FEDORA-2009-12180 (mysql)
8102
8103| [66425] Mandriva Security Advisory MDVSA-2009:326 (mysql)
8104
8105| [66256] Fedora Core 11 FEDORA-2009-10701 (ocaml-mysql)
8106
8107| [66251] Fedora Core 10 FEDORA-2009-10582 (ocaml-mysql)
8108
8109| [66056] Debian Security Advisory DSA 1910-1 (mysql-ocaml)
8110
8111| [66035] Mandrake Security Advisory MDVSA-2009:279 (ocaml-mysql)
8112
8113| [65937] SLES10: Security update for MySQL
8114
8115| [65884] SLES10: Security update for MySQL
8116
8117| [65827] SLES10: Security update for MySQL
8118
8119| [65710] SLES11: Security update for MySQL
8120
8121| [65610] SLES9: Security update for MySQL
8122
8123| [65566] SLES9: Security update for MySQL
8124
8125| [65507] SLES9: Security update for MySQL
8126
8127| [65502] SLES9: Security update for mysql
8128
8129| [65426] SLES9: Security update for MySQL
8130
8131| [65385] SLES9: Security update for mysql
8132
8133| [65341] SLES9: Security update for MySQL
8134
8135| [65181] SLES9: Security update for MySQL
8136
8137| [65176] SLES9: Security update for MySQL
8138
8139| [64932] CentOS Security Advisory CESA-2009:1289 (mysql)
8140
8141| [64820] Debian Security Advisory DSA 1877-1 (mysql-dfsg-5.0)
8142
8143| [64532] Mandrake Security Advisory MDVSA-2009:189 (apache-mod_auth_mysql)
8144
8145| [64522] Mandrake Security Advisory MDVSA-2009:179 (mysql)
8146
8147| [64461] Mandrake Security Advisory MDVSA-2009:159 (mysql)
8148
8149| [63872] Mandrake Security Advisory MDVSA-2009:094 (mysql)
8150
8151| [63630] FreeBSD Ports: proftpd, proftpd-mysql
8152
8153| [63171] FreeBSD Ports: mysql-server
8154
8155| [63170] FreeBSD Ports: mysql-server
8156
8157| [63169] FreeBSD Ports: mysql-server
8158
8159| [63168] FreeBSD Ports: mysql-server
8160
8161| [63095] FreeBSD Ports: mysql-server
8162
8163| [61852] Debian Security Advisory DSA 1662-1 (mysql-dfsg-5.0)
8164
8165| [61699] FreeBSD Ports: mysql-client
8166
8167| [61656] FreeBSD Ports: proftpd, proftpd-mysql
8168
8169| [61618] FreeBSD Ports: mysql-server
8170
8171| [61599] Gentoo Security Advisory GLSA 200809-04 (mysql)
8172
8173| [61283] Debian Security Advisory DSA 1608-1 (mysql-dfsg-5.0)
8174
8175| [60804] Gentoo Security Advisory GLSA 200804-04 (mysql)
8176
8177| [60271] Debian Security Advisory DSA 1478-1 (mysql-dfsg-5.0)
8178
8179| [60106] Debian Security Advisory DSA 1451-1 (mysql-dfsg-5.0)
8180
8181| [60017] Slackware Advisory SSA:2007-348-01 mysql
8182
8183| [59638] Debian Security Advisory DSA 1413-1 (mysql-dfsg, mysql-dfsg-5.0, mysql-dfsg-4.1)
8184
8185| [59245] Gentoo Security Advisory GLSA 200711-25 (mysql)
8186
8187| [58863] FreeBSD Ports: freeradius, freeradius-mysql
8188
8189| [58545] Gentoo Security Advisory GLSA 200708-10 (mysql)
8190
8191| [58261] Gentoo Security Advisory GLSA 200705-11 (MySQL)
8192
8193| [57859] Gentoo Security Advisory GLSA 200608-09 (mysql)
8194
8195| [57725] FreeBSD Ports: proftpd, proftpd-mysql
8196
8197| [57576] FreeBSD Ports: proftpd, proftpd-mysql
8198
8199| [57527] FreeBSD Ports: mysql-server
8200
8201| [57526] FreeBSD Ports: mysql-server
8202
8203| [57337] Debian Security Advisory DSA 1169-1 (mysql-dfsg-4.1)
8204
8205| [57257] FreeBSD Ports: mysql-server
8206
8207| [57167] Slackware Advisory SSA:2006-211-01 mysql
8208
8209| [57109] Debian Security Advisory DSA 1112-1 (mysql-dfsg-4.1)
8210
8211| [56964] Gentoo Security Advisory GLSA 200606-18 (pam_mysql)
8212
8213| [56940] Gentoo Security Advisory GLSA 200606-13 (MySQL)
8214
8215| [56924] Debian Security Advisory DSA 1092-1 (mysql-dfsg-4.1)
8216
8217| [56861] Slackware Advisory SSA:2006-155-01 mysql
8218
8219| [56850] FreeBSD Ports: mysql-server
8220
8221| [56849] FreeBSD Ports: mysql-server
8222
8223| [56833] Debian Security Advisory DSA 1079-1 (mysql-dfsg)
8224
8225| [56789] Debian Security Advisory DSA 1073-1 (mysql-dfsg-4.1)
8226
8227| [56788] Debian Security Advisory DSA 1071-1 (mysql)
8228
8229| [56730] Slackware Advisory SSA:2006-129-02 mysql
8230
8231| [56728] Gentoo Security Advisory GLSA 200605-13 (MySQL)
8232
8233| [56714] FreeBSD Ports: mysql-server
8234
8235| [55520] Debian Security Advisory DSA 833-2 (mysql-dfsg-4.1)
8236
8237| [55514] Debian Security Advisory DSA 833-1 (mysql-dfsg-4.1)
8238
8239| [55493] Debian Security Advisory DSA 829-1 (mysql)
8240
8241| [55492] Debian Security Advisory DSA 831-1 (mysql-dfsg)
8242
8243| [55164] Debian Security Advisory DSA 783-1 (mysql-dfsg-4.1)
8244
8245| [54884] Gentoo Security Advisory GLSA 200503-19 (mysql)
8246
8247| [54819] Gentoo Security Advisory GLSA 200501-33 (mysql)
8248
8249| [54713] Gentoo Security Advisory GLSA 200410-22 (MySQL)
8250
8251| [54659] Gentoo Security Advisory GLSA 200409-02 (MySQL)
8252
8253| [54580] Gentoo Security Advisory GLSA 200405-20 (MySQL)
8254
8255| [54483] FreeBSD Ports: proftpd, proftpd-mysql
8256
8257| [54201] FreeBSD Ports: mysql-server
8258
8259| [53776] Debian Security Advisory DSA 013-1 (mysql)
8260
8261| [53755] Debian Security Advisory DSA 483-1 (mysql)
8262
8263| [53750] Debian Security Advisory DSA 707-1 (mysql)
8264
8265| [53666] Debian Security Advisory DSA 381-1 (mysql)
8266
8267| [53595] Debian Security Advisory DSA 303-1 (mysql)
8268
8269| [53585] Debian Security Advisory DSA 212-1 (mysql)
8270
8271| [53481] Debian Security Advisory DSA 647-1 (mysql)
8272
8273| [53251] Debian Security Advisory DSA 562-1 (mysql)
8274
8275| [53230] Debian Security Advisory DSA 540-1 (mysql)
8276
8277| [52466] FreeBSD Ports: exim, exim-ldap2, exim-mysql, exim-postgresql
8278
8279| [52459] FreeBSD Ports: mysql-client
8280
8281| [52419] FreeBSD Ports: mysql-scripts
8282
8283| [52406] FreeBSD Ports: mysql-server
8284
8285| [52375] FreeBSD Ports: mysql-server, mysql-client
8286
8287| [52274] FreeBSD Ports: mysql-server
8288
8289| [52273] FreeBSD Ports: mysql-server
8290
8291| [52272] FreeBSD Ports: mysql-server
8292
8293| [52271] FreeBSD Ports: mysql-server
8294
8295| [52270] FreeBSD Ports: mysql-server
8296
8297| [52233] FreeBSD Ports: mysql-scripts
8298
8299| [52158] FreeBSD Ports: mysql-server
8300
8301| [16093] MySQL Eventum Multiple flaws
8302
8303| [12639] MySQL Authentication bypass through a zero-length password
8304
8305| [10783] PCCS-Mysql User/Password Exposure