substitution software vulnerabilities
vulnerabilities.aspcode.net
Searching substitution software vulnerabilities
Buffer overflow in the AIM and ICQ module in Ga
overflow
|
module
|
before
|
Buffer
|
Gaim
|
AIM
|
ICQ
|
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.
Buffer overflow in the environment variable sub
"$VAR/EVAR=arg"
|
substitution
|
environment
|
LD_PRELOAD
|
arguments
|
variables
|
arbitrary
|
pathname
|
returned
|
variable
|
overflow
|
function
|
appended
|
portion
|
getenv
|
allows
|
Buffer
|
inject
|
which
|
cause
|
mainc
|
local
|
users
|
17-14
|
call
|
code
|
such
|
EVAR
|
form
|
OSH
|
via
|
Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.
Spectrum Cash Receipting System before 6.504 us
Receipting
|
Spectrum
|
before
|
System
|
Cash
|
Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PASSFILE password file, which makes it easier for local users to gain privileges by decrypting a password.
Comvigo IM Lock 2006 uses a simple substitution
Comvigo
|
Lock
|
Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the product's blocking functionality by decrypting the password.
Cross-site scripting (XSS) vulnerability in Rev
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in RevoBoard 1.8, as derived from PunBB, allows remote attackers to inject arbitrary web script or HTML via a substitution cipher of the email tag, which is transformed when the application's e-mail address obfuscator reverses the transformation. NOTE: it is not clear whether this is a site-specific issue; however, the claimed codebase relationship with PunBB might be relevant.
Software vulnerabilities results 1 to 6 of 6
Page:
1