table width software vulnerabilities
vulnerabilities.aspcode.net
Searching table width software vulnerabilities
Remote attackers can crash Lynx and Internet Ex
attackers
|
parameter
|
Internet
|
Explorer
|
Remote
|
width
|
large
|
using
|
crash
|
Lynx
|
can
|
IMG
|
tag
|
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
The permissions for a system-critical NIS+ tabl
system-critical
|
permissions
|
table
|
NIS+
|
The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.
AOL Instant Messenger (AIM) 4.7 allows remote a
Messenger
|
Instant
|
AOL
|
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger than the actual image data.
ICQ 2001b Build 3659 allows remote attackers to
Build
|
2001b
|
ICQ
|
ICQ 2001b Build 3659 allows remote attackers to cause a denial of service (crash) via a malformed picture that contains large height and width values, which causes the crash when viewed in Userdetails.
The Message Session window in Mirabilis ICQ Pro
Mirabilis
|
attackers
|
service
|
Message
|
Session
|
remote
|
allows
|
window
|
denial
|
cause
|
2003a
|
ICQ
|
Pro
|
The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.
Windows Media Player 9 allows remote attackers
containing
|
attackers
|
arbitrary
|
execute
|
Windows
|
Player
|
remote
|
allows
|
large
|
Media
|
file
|
code
|
via
|
PNG
|
Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."
asycpict.dll, as used in Microsoft products suc
asycpictdll
|
Microsoft
|
attackers
|
products
|
service
|
allows
|
remote
|
denial
|
Front
|
cause
|
used
|
such
|
Page
|
asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.
Mozilla 1.6 and possibly other versions allows
attackers
|
versions
|
possibly
|
Mozilla
|
service
|
denial
|
allows
|
remote
|
other
|
cause
|
Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a large (1) height or (2) width value.
GIF file validation error in MSN Messenger 6.2
validation
|
arbitrary
|
Messenger
|
attackers
|
improper
|
contact
|
execute
|
height
|
user's
|
allows
|
remote
|
error
|
image
|
width
|
file
|
code
|
list
|
GIF
|
via
|
MSN
|
GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.
gifload.exe in GIMP 2.0.5, 2.2.3, and possibly
gifloadexe
|
GIMP
|
gifload.exe in GIMP 2.0.5, 2.2.3, and possibly 2.2.4 allows remote attackers or local users to cause a denial of service (application crash) via the image descriptor (1) height or (2) width fields set to zero.
User32.DLL in Microsoft Windows 98SE, and possi
attackers
|
operating
|
Microsoft
|
User32DLL
|
possibly
|
service
|
systems
|
Windows
|
remote
|
denial
|
allows
|
other
|
cause
|
local
|
98SE
|
User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.
Firefox before 1.0.7 and Mozilla Suite before 1
Firefox
|
before
|
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.
Integer overflow in Apple Quicktime before 7.0.
Quicktime
|
overflow
|
Integer
|
before
|
Apple
|
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags.
Microsoft Internet Explorer 6.0.2900.2180 allow
Microsoft
|
Explorer
|
Internet
|
Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript.
The Cisco Intrusion Prevention System (IPS) and
Prevention
|
Intrusion
|
System
|
Cisco
|
The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
Check Point Web Intelligence does not properly
Intelligence
|
half-width
|
full-width
|
character
|
encodings
|
detection
|
attackers
|
properly
|
traffic
|
Unicode
|
certain
|
remote
|
handle
|
evade
|
Check
|
Point
|
allow
|
which
|
might
|
HTTP
|
does
|
not
|
Web
|
Check Point Web Intelligence does not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
Multiple IBM ISS Proventia Series products, inc
full-width
|
half-width
|
attackers
|
including
|
character
|
encodings
|
Proventia
|
detection
|
Multiple
|
products
|
properly
|
Unicode
|
traffic
|
certain
|
remote
|
handle
|
Series
|
evade
|
allow
|
which
|
might
|
HTTP
|
ISS
|
not
|
IBM
|
Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
The 3Com TippingPoint IPS do not properly handl
TippingPoint
|
half-width
|
full-width
|
character
|
detection
|
attackers
|
encodings
|
properly
|
request
|
traffic
|
certain
|
Unicode
|
remote
|
handle
|
allow
|
evade
|
might
|
which
|
HTTP
|
3Com
|
POST
|
not
|
IPS
|
The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic.
MySQL Community Server before 5.0.45 does not r
Community
|
before
|
Server
|
MySQL
|
MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.
MySQL Community Server before 5.0.45 allows rem
Community
|
before
|
Server
|
MySQL
|
MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table.
Software vulnerabilities results 1 to 20 of 206
Page:
1
2
3
4
5
...
11
►