violation software vulnerabilities
vulnerabilities.aspcode.net
Searching violation software vulnerabilities
counter.exe 2.70 allows a remote attacker to ca
counterexe
|
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.
The URLConnection function in MacOS Runtime Jav
URLConnection
|
function
|
Runtime
|
MacOS
|
Java
|
The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.
Mailtool for OpenWindows 3.6, 3.6.1, and 3.6.2
OpenWindows
|
Mailtool
|
Mailtool for OpenWindows 3.6, 3.6.1, and 3.6.2 allows remote attackers to cause a denial of service (mailtool segmentation violation and crash) via a malformed mail attachment.
Buffer overflow in CHttpServer::OnParseError in
overflow
|
Buffer
|
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.
BEA WebLogic Server and Express 7.0 and 7.0.0.1
WebLogic
|
Express
|
Server
|
BEA
|
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to conduct unauthorized activities in violation of the intended restrictions.
Baby FTP Server (BabyFTP) 1.2, and possibly oth
Server
|
Baby
|
FTP
|
Baby FTP Server (BabyFTP) 1.2, and possibly other versions before May 31, 2003, allows remote attackers to cause a denial of service via a large number of connections from the same IP address, which triggers an access violation.
XDM in XFree86 opens a chooserFd TCP socket eve
DisplayManagerrequestPort
|
restrictions
|
violation
|
attackers
|
chooserFd
|
intended
|
XFree86
|
connect
|
remote
|
socket
|
allow
|
opens
|
which
|
could
|
port
|
even
|
XDM
|
TCP
|
XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.
WarFTPD 1.82 RC9, when running as an NT service
WarFTPD
|
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.
BEA WebLogic Server and WebLogic Express 7.0 th
application
|
constraints
|
redeployed
|
violation
|
mappings
|
security
|
WebLogic
|
continue
|
without
|
through
|
Express
|
Service
|
changed
|
allows
|
Server
|
access
|
having
|
newly
|
again
|
users
|
which
|
those
|
Pack
|
role
|
does
|
BEA
|
out
|
may
|
not
|
log
|
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.
The InstallTrigger.install method in Firefox be
InstallTriggerinstall
|
Firefox
|
before
|
method
|
The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.
Firefox before 1.0.5, Mozilla before 1.7.9, and
Firefox
|
before
|
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.
The E4X implementation in Mozilla Firefox befor
implementation
|
Firefox
|
Mozilla
|
before
|
E4X
|
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.
RITLabs The Bat! before 3.0.0.15 displays certa
RITLabs
|
before
|
Bat
|
RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.
MSO.DLL in Microsoft Office 2000, Office XP (20
Microsoft
|
Office
|
MSODLL
|
MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt. NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode "Sheet Name" string.
Neon Responder 5.4 for LANsurveyor allows remot
LANsurveyor
|
attackers
|
Responder
|
service
|
denial
|
allows
|
remote
|
cause
|
Neon
|
Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packet that triggers an access violation.
The substr_compare function in string.c in PHP
substr_compare
|
function
|
stringc
|
PHP
|
The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.
Unspecified vulnerability in session.c in PHP b
vulnerability
|
Unspecified
|
sessionc
|
before
|
PHP
|
Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown impact and attack vectors, related to "certain characters in session names," including special characters that are frequently associated with CRLF injection, SQL injection, cross-site scripting (XSS), and HTTP response splitting vulnerabilities. NOTE: while the nature of the vulnerability is unspecified, it is likely that this is related to a violation of an expectation by PHP applications that the session name is alphanumeric, as implied in the PHP manual for session_name().
Double free vulnerability in PHP before 4.4.7,
vulnerability
|
before
|
Double
|
free
|
PHP
|
Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.
The server in Toribash 2.71 and earlier does no
Toribash
|
server
|
The server in Toribash 2.71 and earlier does not properly handle long commands, which allows remote attackers to trigger a protocol violation in which data is sent to other clients without a required LF character, as demonstrated by a SAY command. NOTE: the security impact of this violation is not clear, although it probably makes exploitation of CVE-2007-4449 easier.
The zend_alter_ini_entry function in PHP before
zend_alter_ini_entry
|
function
|
before
|
PHP
|
The zend_alter_ini_entry function in PHP before 5.2.4 does not properly handle an interruption to the flow of execution triggered by a memory_limit violation, which has unknown impact and attack vectors.
Software vulnerabilities results 1 to 20 of 25
Page:
1
2
►