unless modified since software vulnerabilities
vulnerabilities.aspcode.net
Searching unless modified since software vulnerabilities
Buffer overflow in htdigest in Apache 1.3.26 an
htdigest
|
overflow
|
Apache
|
Buffer
|
Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
** DISPUTED ** Format string bug in the open_al
open_altfile
|
filenamec
|
DISPUTED
|
function
|
Format
|
string
|
less
|
GNU
|
bug
|
** DISPUTED ** Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless there are plausible scenarios under which privilege boundaries could be crossed.
Buffer overflow in htdigest in Apache 2.0.52 ma
htdigest
|
overflow
|
Apache
|
Buffer
|
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
** DISPUTED ** Sudo 1.6.8p7 on SuSE Linux 9.3,
distributions
|
privileges
|
possibly
|
entering
|
password
|
DISPUTED
|
hitting
|
allows
|
CTRL-C
|
blank
|
using
|
168p7
|
other
|
Linux
|
users
|
local
|
Sudo
|
SuSE
|
gain
|
call
|
then
|
** DISPUTED ** Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns an empty string for the password so I don't see how this could happen unless the user's actual password was empty."
** DISPUTED ** NOTE: this issue has been dispu
DISPUTED
|
** DISPUTED ** NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. NOTE: the vendor says that since only one character can be modified, there is no SQL injection. Thus this might be an "invalid SQL syntax error." Multiple followups support the vendor.
Unspecified vulnerability in Positive Software
vulnerability
|
Corporation
|
Unspecified
|
Software
|
Positive
|
CP+
|
Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to has unknown impact and attack vectors, related to "a possible security flaw caused by a bug in Perl." NOTE: unless CP+ includes its own copy of Perl with CVE-2005-3962, this is a different vulnerability than CVE-2005-3962; however, there is insufficient information to be sure.
Buffer overflow in sysctl in the Linux Kernel 2
overflow
|
Kernel
|
before
|
Buffer
|
sysctl
|
Linux
|
Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer. NOTE: since the sysctl is called from a userland program that provides the argument, this might not be a vulnerability, unless a legitimate user-assisted or setuid scenario can be identified.
Buffer overflow in UnZip 5.50 and earlier allow
overflow
|
Buffer
|
UnZip
|
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.
** DISPUTED ** Buffer overflow in mIRC 5.91, 6.
overflow
|
DISPUTED
|
Buffer
|
mIRC
|
** DISPUTED ** Buffer overflow in mIRC 5.91, 6.03, 6.12, and 6.16 allows local users to execute arbitrary code via a long string that is entered after reaching the DCC Get Folder Dialog. NOTE: this issue has been disputed by the vendor, saying "as far as I can tell, this is neither an exploit nor a vulnerability. The above report describes a local bug in mIRC." It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk.
** DISPUTED ** Buffer overflow in the font comm
overflow
|
probably
|
DISPUTED
|
command
|
Buffer
|
mIRC
|
font
|
** DISPUTED ** Buffer overflow in the font command of mIRC, probably 6.16, allows local users to execute arbitrary code via a long string. NOTE: the original researcher claims that issue has been disputed by the vendor, and that the vendor stated "as far as I can tell, this is neither an exploit nor a vulnerability. The above report describes a local bug in mIRC." It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk.
Oracle Database 8i, 9i, and 10g allow remote au
AUTH_ALTER_SESSION
|
authentication
|
authenticated
|
Transparent
|
privileged
|
statements
|
Substrate
|
attribute
|
including
|
arbitrary
|
Database
|
accounts
|
modified
|
logging
|
Network
|
context
|
execute
|
Oracle
|
create
|
bypass
|
remote
|
phase
|
audit
|
users
|
allow
|
user
|
10g
|
SQL
|
via
|
new
|
SYS
|
Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB18 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0265.
Unspecified vulnerability in main.php in an uns
vulnerability
|
Development
|
Unspecified
|
Bruinsma"
|
possibly
|
FleXiBle
|
mainphp
|
created
|
Andries
|
"file
|
Unspecified vulnerability in main.php in an unspecified "file created by Andries Bruinsma," possibly a FleXiBle Development (FXB) application, allows remote attackers to include and execute arbitrary PHP code. NOTE: this disclosure is extremely vague and has very little information about the specific vulnerability type. In addition, there is little public information on the named product. Finally, an XSS vector is implied in the subject line, but because there is no other information and evidence of a cut-and-paste error, it will not be assigned a separate CVE identifier unless additional information is provided.
Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6
Safari
|
Apple
|
Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the operation of the system outside of the scope of Safari itself.
Mozilla Firefox 2.0.0.6 and earlier allows remo
Firefox
|
Mozilla
|
Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the contents of the status bar via a link to a data: URI containing an encoded URL. NOTE: the severity of this issue has been disputed by a reliable third party, since the intended functionality of the status bar allows it to be modified.
PHP before 5.2.3 allows context-dependent attac
before
|
PHP
|
PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function; or (2) a long string in the string parameter to the fnmatch function, accompanied by a pattern parameter value with undefined characteristics, as demonstrated by a "*[1]e" value. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.
The iconv_substr function in PHP 5.2.4 and earl
iconv_substr
|
function
|
PHP
|
The iconv_substr function in PHP 5.2.4 and earlier allows context-dependent attackers to cause (1) a denial of service (application crash) via a long string in the charset parameter, probably also requiring a long string in the str parameter; or (2) a denial of service (temporary application hang) via a long string in the str parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.
The setlocale function in PHP before 5.2.4 allo
setlocale
|
function
|
before
|
PHP
|
The setlocale function in PHP before 5.2.4 allows context-dependent attackers to cause a denial of service (application crash) via a long string in the locale parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.
PHP 5.2.4 and earlier allows context-dependent
PHP
|
PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.
** DISPUTED ** PHP remote file inclusion vulne
form/db_form/employeephp
|
vulnerability
|
inclusion
|
DISPUTED
|
PHPortal
|
remote
|
file
|
PHP
|
** DISPUTED ** PHP remote file inclusion vulnerability in form/db_form/employee.php in PHPortal 0.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: this issue is disputed by CVE, since DOCUMENT_ROOT cannot be modified by an attacker.
Multiple buffer overflows in iMatix Xitami Web
If-Modified-Since
|
attackers
|
arbitrary
|
overflows
|
Multiple
|
execute
|
remote
|
iMatix
|
buffer
|
Xitami
|
Server
|
header
|
allow
|
long
|
25c2
|
code
|
Web
|
via
|
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long If-Modified-Since header to (1) xigui32.exe or (2) xitami.exe.
Software vulnerabilities results 1 to 20 of 407
Page:
1
2
3
4
5
...
21
►