| Name |
Description |
| CVE-2018-9302 |
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in
Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary
files or send TCP traffic to intranet hosts via the url parameter.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2017-14611, which was about version 0.13.0, which (surprisingly)
is an earlier version than 0.4.4.
|
| CVE-2018-9110 |
Studio 42 elFinder before 2.1.37 has a directory traversal
vulnerability in elFinder.class.php with the zipdl() function that can
allow a remote attacker to download files accessible by the web server
process and delete files owned by the account running the web server
process. NOTE: this issue exists because of an incomplete fix for
CVE-2018-9109.
|
| CVE-2018-7886 |
An issue was discovered in CloudMe 1.11.0. An unauthenticated local
attacker that can connect to the "CloudMe Sync" client application
listening on 127.0.0.1 port 8888 can send a malicious payload causing
a buffer overflow condition. This will result in code execution, as
demonstrated by a TCP reverse shell, or a crash. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2018-6892.
|
| CVE-2018-7489 |
FasterXML jackson-databind before 2.8.11.1 and 2.9.x before 2.9.5
allows unauthenticated remote code execution because of an incomplete
fix for the CVE-2017-7525 deserialization flaw. This is exploitable by
sending maliciously crafted JSON input to the readValue method of the
ObjectMapper, bypassing a blacklist that is ineffective if the c3p0
libraries are available in the classpath.
|
| CVE-2018-7440 |
An issue was discovered in Leptonica through 1.75.3. The
gplotMakeOutput function allows command injection via a $(command)
approach in the gplot rootname argument. This issue exists because of
an incomplete fix for CVE-2018-3836.
|
| CVE-2018-7170 |
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows
authenticated users that know the private symmetric key to create
arbitrarily-many ephemeral associations in order to win the clock
selection of ntpd and modify a victim's clock via a Sybil attack. This
issue exists because of an incomplete fix for CVE-2016-1549.
|
| CVE-2018-7054 |
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1.
There is a use-after-free when a server is disconnected during
netsplits. NOTE: this issue exists because of an incomplete fix for
CVE-2017-7191.
|
| CVE-2018-6831 |
The setSystemTime function in Foscam Cameras C1 Lite V3, and C1 V3
with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P
V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2,
FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1
V2, C1 Lite, and C1 Lite V2 2.52.2.47 and earlier, FI9800P, FI9800P
V2, FI9803P V2, FI9803P V3, and FI9851P V2 2.54.2.47 and earlier,
FI9815P, FI9815P V2, FI9816P, and FI9816P V2, 2.51.2.47 and earlier,
R2 and R4 2.71.1.59 and earlier, C2 and FI9961EP 2.72.1.59 and
earlier, FI9900EP, FI9900P, and FI9901EP 2.74.1.59 and earlier,
FI9928P 2.74.1.58 and earlier, FI9803EP and FI9853EP 2.22.2.31 and
earlier, FI9803P and FI9851P 2.24.2.31 and earlier, FI9821P V2,
FI9826P V2, FI9831P V2, and FI9821EP 2.21.2.31 and earlier, FI9821W
V2, FI9831W, FI9826W, FI9821P, FI9831P, and FI9826P 2.11.1.120 and
earlier, FI9818W V2 2.13.2.120 and earlier, FI9805W, FI9804W, FI9804P,
FI9805E, and FI9805P 2.14.1.120 and earlier, FI9828P, and FI9828W
2.13.1.120 and earlier, and FI9828P V2 2.11.1.133 and earlier allows
remote authenticated users to execute arbitrary commands via a ';' in
the ntpServer argument. NOTE: this issue exists because of an
incomplete fix for CVE-2017-2849.
|
| CVE-2018-5968 |
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3
allows unauthenticated remote code execution because of an incomplete
fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws.
This is exploitable via two different gadgets that bypass a blacklist.
|
| CVE-2018-18867 |
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4
via the upload.php url parameter. NOTE: this issue exists because of an
incomplete fix for CVE-2018-15495.
|
| CVE-2018-18559 |
In the Linux kernel through 4.19, a use-after-free can occur due to a
race condition between fanout_add from setsockopt and bind on an
AF_PACKET socket. This issue exists because of the
15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a race
condition. The code mishandles a certain multithreaded case involving a
packet_do_bind unregister action followed by a packet_notifier
register action. Later, packet_release operates on only one of the two
applicable linked lists. The attacker can achieve Program Counter
control.
|
| CVE-2018-17961 |
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a
sandbox protection mechanism via vectors involving errorhandler setup.
NOTE: this issue exists because of an incomplete fix for
CVE-2018-17183.
|
| CVE-2018-17886 |
An issue was discovered in JEESNS 1.3. The XSS filter in
com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java could be
bypassed, as demonstrated by a <svg/onLoad=confirm substring. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2018-12429.
|
| CVE-2018-17854 |
SIMDComp before 0.1.1 allows remote attackers to cause a denial of
service (heap-based buffer over-read and application crash) because it
can read (and then discard) extra bytes. NOTE: this issue exists
because of an incomplete fix for CVE-2018-17427.
|
| CVE-2018-15895 |
An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because
the remote function in app/spider/spider_tools.class.php does not block
DNS hostnames associated with private and reserved IP addresses, as
demonstrated by 127.0.0.1 in an A record. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2018-14858.
|
| CVE-2018-14858 |
An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11
because the remote function in app/spider/spider_tools.class.php does
not block private and reserved IP addresses such as 10.0.0.0/8. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2018-14514.
|
| CVE-2018-11408 |
The security handlers in the Security component in Symfony in 2.7.x
before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before
3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability
when security.http_utils is inlined by a container. NOTE: this issue
exists because of an incomplete fix for CVE-2017-16652.
|
| CVE-2018-11407 |
An issue was discovered in the Ldap component in Symfony 2.8.x before
2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before
4.0.7. It allows remote attackers to bypass authentication by logging
in with a "null" password and valid username, which triggers an
unauthenticated bind. NOTE: this issue exists because of an incomplete
fix for CVE-2016-2403.
|
| CVE-2018-11105 |
There is stored cross site scripting in the wp-live-chat-support plugin
before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email"
(aka wplc_email) input fields to
wp-json/wp_live_chat_support/v1/start_chat whenever a malicious
attacker would initiate a new chat with an administrator. NOTE: this
issue exists because of an incomplete fix for CVE-2018-9864.
|
| CVE-2018-10992 |
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings
before launching the program specified by the BROWSER environment
variable, which allows remote attackers to conduct argument-injection
attacks via a crafted URL, as demonstrated by a --proxy-pac-file
argument, because the GNU Guile code uses the system Scheme procedure
instead of the system* Scheme procedure. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2017-17523.
|
| CVE-2018-10809 |
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys)
allows local users to cause a denial of service (BSOD) or possibly have
unspecified other impact because of not validating input values from
IOCtl 0x00222040. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2018-8873.
|
| CVE-2018-10547 |
An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36,
7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There
is Reflected XSS on the PHAR 403 and 404 error pages via request data
of a request for a .phar file. NOTE: this vulnerability exists because
of an incomplete fix for CVE-2018-5712.
|
| CVE-2018-0489 |
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service
Provider before 2.6.1.4 on Windows and other products, mishandles
digital signatures of user data, which allows remote attackers to
obtain sensitive information or conduct impersonation attacks via
crafted XML data. NOTE: this issue exists because of an incomplete fix
for CVE-2018-0486.
|
| CVE-2017-9951 |
The try_read_command function in memcached.c in memcached before 1.4.39
allows remote attackers to cause a denial of service (segmentation
fault) via a request to add/set a key, which makes a comparison between
signed and unsigned int and triggers a heap-based buffer over-read.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2016-8705.
|
| CVE-2017-9804 |
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an
application allows entering a URL in a form field and built-in
URLValidator is used, it is possible to prepare a special URL which
will be used to overload server process when performing validation of
the URL. NOTE: this vulnerability exists because of an incomplete fix
for S2-047 / CVE-2017-7672.
|
| CVE-2017-9050 |
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based
buffer over-read in the xmlDictAddString function in dict.c. This
vulnerability causes programs that use libxml2, such as PHP, to crash.
This vulnerability exists because of an incomplete fix for
CVE-2016-1839.
|
| CVE-2017-9049 |
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based
buffer over-read in the xmlDictComputeFastKey function in dict.c. This
vulnerability causes programs that use libxml2, such as PHP, to crash.
This vulnerability exists because of an incomplete fix for libxml2 Bug
759398.
|
| CVE-2017-8921 |
In FlightGear before 2017.2.1, the FGCommand interface allows
overwriting any file the user has write access to, but not with
arbitrary data: only with the contents of a FlightGear flightplan
(XML). A resource such as a malicious third-party aircraft could
exploit this to damage files belonging to the user. Both this issue and
CVE-2016-9956 are directory traversal vulnerabilities in
Autopilot/route_mgr.cxx - this one exists because of an incomplete fix
for CVE-2016-9956.
|
| CVE-2017-8384 |
Craft CMS before 2.6.2976 allows XSS attacks because an array returned
by HttpRequestService::getSegments() and getActionSegments() need not
be zero-based. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2017-8052.
|
| CVE-2017-8039 |
An issue was discovered in Pivotal Spring Web Flow through 2.4.5.
Applications that do not change the value of the MvcViewFactoryCreator
useSpringBinding property which is disabled by default (i.e., set to
'false') can be vulnerable to malicious EL expressions in view states
that process form submissions but do not have a sub-element to declare
explicit data binding property mappings. NOTE: this issue exists
because of an incomplete fix for CVE-2017-4971.
|
| CVE-2017-7578 |
Multiple heap-based buffer overflows in parser.c in libming 0.4.7 allow
remote attackers to cause a denial of service (listswf application
crash) or possibly have unspecified other impact via a crafted SWF
file. NOTE: this issue exists because of an incomplete fix for
CVE-2016-9831.
|
| CVE-2017-7275 |
The ReadPCXImage function in coders/pcx.c in ImageMagick 7.0.4.9 allows
remote attackers to cause a denial of service (attempted large memory
allocation and application crash) via a crafted file. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2016-8862 and
CVE-2016-8866.
|
| CVE-2017-7263 |
The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows
remote attackers to cause a denial of service (heap-based buffer
over-read and application crash) or possibly have unspecified other
impact via a crafted BMP image. NOTE: this vulnerability exists because
of an incomplete fix for CVE-2016-8698.
|
| CVE-2017-7221 |
OpenText Documentum Content Server has an inadequate protection
mechanism against SQL injection, which allows remote authenticated
users to execute arbitrary code with super-user privileges by
leveraging the availability of the dm_bp_transition docbase method with
a user-created dm_procedure object, as demonstrated by use of a
backspace character in an injected string. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2014-2513.
|
| CVE-2017-7220 |
OpenText Documentum Content Server allows superuser access via
sys_obj_save or save of a crafted object, followed by an unauthorized
"UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC
save-commands" attack. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2015-4532.
|
| CVE-2017-6001 |
Race condition in kernel/events/core.c in the Linux kernel before
4.9.7 allows local users to gain privileges via a crafted application
that makes concurrent perf_event_open system calls for moving a
software group into a hardware context. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2016-6786.
|
| CVE-2017-5940 |
Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not
comprehensively address dotfile cases during its attempt to prevent
accessing user files with an euid of zero, which allows local users to
conduct sandbox-escape attacks via vectors involving a symlink and the
--private option. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2017-5180.
|
| CVE-2017-5668 |
bitlbee-libpurple before 3.5.1 allows remote attackers to cause a
denial of service (NULL pointer dereference and crash) and possibly
execute arbitrary code via a file transfer request for a contact that
is not in the contact list. NOTE: this vulnerability exists because of
an incomplete fix for CVE-2016-10189.
|
| CVE-2017-5585 |
OpenText Documentum Content Server (formerly EMC Documentum Content
Server) 7.3, when PostgreSQL Database is used and
return_top_results_row_based config option is false, does not properly
restrict DQL hints, which allows remote authenticated users to conduct
DQL injection attacks and execute arbitrary DML or DDL commands via a
crafted request. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-2520.
|
| CVE-2017-5551 |
The simple_set_acl function in fs/posix_acl.c in the Linux kernel
before 4.9.6 preserves the setgid bit during a setxattr call involving
a tmpfs filesystem, which allows local users to gain group privileges
by leveraging the existence of a setgid program with restrictions on
execute permissions. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2016-7097.
|
| CVE-2017-17485 |
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3
allows unauthenticated remote code execution because of an incomplete
fix for the CVE-2017-7525 deserialization flaw. This is exploitable by
sending maliciously crafted JSON input to the readValue method of the
ObjectMapper, bypassing a blacklist that is ineffective if the Spring
libraries are available in the classpath.
|
| CVE-2017-14695 |
Directory traversal vulnerability in minion id validation in SaltStack
Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before
2017.7.2 allows remote minions with incorrect credentials to
authenticate to a master via a crafted minion ID. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2017-12791.
|
| CVE-2017-14177 |
Apport through 2.20.7 does not properly handle core dumps from setuid
binaries allowing local users to create certain files as root which an
attacker could leverage to perform a denial of service via resource
exhaustion or possibly gain root privileges. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2015-1324.
|
| CVE-2017-14164 |
A size-validation issue was discovered in opj_j2k_write_sot in
lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an
out-of-bounds write, which may lead to remote denial of service
(heap-based buffer overflow affecting opj_write_bytes_LE in
lib/openjp2/cio.c) or possibly remote code execution. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2017-14152.
|
| CVE-2017-14136 |
OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds
write error in the function FillColorRow1 in utils.cpp when reading an
image file by using cv::imread. NOTE: this vulnerability exists because
of an incomplete fix for CVE-2017-12597.
|
| CVE-2017-14103 |
The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in
GraphicsMagick 1.3.26 do not properly manage image pointers after
certain error conditions, which allows remote attackers to conduct
use-after-free attacks via a crafted file, related to a ReadMNGImage
out-of-order CloseBlob call. NOTE: this vulnerability exists because of
an incomplete fix for CVE-2017-11403.
|
| CVE-2017-12066 |
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in
Cacti before 1.1.16 allows remote authenticated users to inject
arbitrary web script or HTML via specially crafted HTTP Referer
headers, related to the $cancel_url variable. NOTE: this vulnerability
exists because of an incomplete fix (lack of the htmlspecialchars
ENT_QUOTES flag) for CVE-2017-11163.
|
| CVE-2017-11411 |
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY
dissector could crash or exhaust system memory. This was addressed in
epan/dissectors/packet-opensafety.c by adding length validation. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2017-9350.
|
| CVE-2017-11410 |
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML
dissector could go into an infinite loop, triggered by packet injection
or a malformed capture file. This was addressed in
epan/dissectors/packet-wbxml.c by adding validation of the
relationships between indexes and lengths. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2017-7702.
|
| CVE-2017-11352 |
In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash
because of incorrect EOF handling in coders/rle.c. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2017-9144.
|
| CVE-2017-0360 |
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote
authenticated users with certain permissions to read arbitrary files
via a "same root name but with a suffix" attack. NOTE: This
vulnerability exists because of an incomplete fix for CVE-2016-1242.
|
| CVE-2017-0038 |
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows
Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows
8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10
Gold, 1511, and 1607 allows remote attackers to obtain sensitive
information from process heap memory via a crafted EMF file, as
demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device
Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or
CVE-2016-3220.
|
| CVE-2016-9936 |
The unserialize implementation in ext/standard/var.c in PHP 7.x before
7.0.14 allows remote attackers to cause a denial of service
(use-after-free) or possibly have unspecified other impact via crafted
serialized data. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2015-6834.
|
| CVE-2016-9773 |
Heap-based buffer overflow in the IsPixelGray function in
MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote
attackers to cause a denial of service (out-of-bounds heap read) via a
crafted image file. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2016-9556.
|
| CVE-2016-9565 |
MagpieRSS, as used in the front-end component in Nagios Core before
4.2.2 might allow remote attackers to read or write to arbitrary files
by spoofing a crafted response from the Nagios RSS feed server. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2008-4796.
|
| CVE-2016-9448 |
The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote
attackers to cause a denial of service (NULL pointer dereference and
crash) by setting the tags TIFF_SETGET_C16ASCII or
TIFF_SETGET_C32_ASCII to values that access 0-byte arrays. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2016-9297.
|
| CVE-2016-8884 |
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5
allows remote attackers to cause a denial of service (NULL pointer
dereference) by calling the imginfo command with a crafted BMP image.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2016-8690.
|
| CVE-2016-8866 |
The AcquireMagickMemory function in MagickCore/memory.c in
ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have
unspecified impact via a crafted image, which triggers a memory
allocation failure. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2016-8862.
|
| CVE-2016-8671 |
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not
properly perform modular exponentiation, which might allow remote
attackers to predict the secret key via unspecified vectors. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2016-6887.
|
| CVE-2016-7147 |
Cross-site scripting (XSS) vulnerability in the manage_findResult
component in the search feature in Zope ZMI in Plone before 4.3.12 and
5.x before 5.0.7 allows remote attackers to inject arbitrary web script
or HTML via vectors involving double quotes, as demonstrated by the
obj_ids:tokens parameter. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2016-7140.
|
| CVE-2016-6330 |
The server in Red Hat JBoss Operations Network (JON), when SSL
authentication is not configured for JON server / agent communication,
allows remote attackers to execute arbitrary code via a crafted HTTP
request, related to message deserialization. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2016-3737.
|
| CVE-2016-6225 |
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does
not properly set the initialization vector (IV) for encryption, which
makes it easier for context-dependent attackers to obtain sensitive
information from encrypted backup files via a Chosen-Plaintext attack.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2013-6394.
|
| CVE-2016-6224 |
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap
partition from activating during boot when using GPT partitioning on a
(1) NVMe or (2) MMC drive, which allows local users to obtain
sensitive information via unspecified vectors. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2015-8946.
|
| CVE-2016-5715 |
Open redirect vulnerability in the Console in Puppet Enterprise 2015.x
and 2016.x before 2016.4.0 allows remote attackers to redirect users
to arbitrary web sites and conduct phishing attacks via a // (slash
slash) followed by a domain in the redirect parameter. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2015-6501.
|
| CVE-2016-5300 |
The XML parser in Expat does not use sufficient entropy for hash
initialization, which allows context-dependent attackers to cause a
denial of service (CPU consumption) via crafted identifiers in an XML
document. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2012-0876.
|
| CVE-2016-5095 |
Integer overflow in the php_escape_html_entities_ex function in
ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22
allows remote attackers to cause a denial of service or possibly have
unspecified other impact by triggering a large output string from a
FILTER_SANITIZE_FULL_SPECIAL_CHARS filter_var call. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2016-5094.
|
| CVE-2016-4956 |
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a
denial of service (interleaved-mode transition and time change) via a
spoofed broadcast packet. NOTE: this vulnerability exists because of
an incomplete fix for CVE-2016-1548.
|
| CVE-2016-4574 |
Off-by-one error in the append_utf8_value function in the DN decoder
(dn.c) in Libksba before 1.3.4 allows remote attackers to cause a
denial of service (out-of-bounds read) via invalid utf-8 encoded data.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2016-4356.
|
| CVE-2016-4472 |
The overflow protection in Expat is removed by compilers with certain
optimization settings, which allows remote attackers to cause a denial
of service (crash) or possibly execute arbitrary code via crafted XML
data. NOTE: this vulnerability exists because of an incomplete fix for
CVE-2015-1283 and CVE-2015-2716.
|
| CVE-2016-4461 |
Apache Struts 2.x before 2.3.29 allows remote attackers to execute
arbitrary code via a "%{}" sequence in a tag attribute, aka forced
double OGNL evaluation. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2016-0785.
|
| CVE-2016-3706 |
Stack-based buffer overflow in the getaddrinfo function in
sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6)
allows remote attackers to cause a denial of service (crash) via
vectors involving hostent conversion. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2013-4458.
|
| CVE-2016-2097 |
Directory traversal vulnerability in Action View in Ruby on Rails
before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to
read arbitrary files by leveraging an application's unrestricted use
of the render method and providing a .. (dot dot) in a pathname. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2016-0752.
|
| CVE-2016-2004 |
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before
9.06 allow remote attackers to execute arbitrary code via unspecified
vectors related to lack of authentication. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2014-2623.
|
| CVE-2016-1967 |
Mozilla Firefox before 45.0 does not properly restrict the
availability of IFRAME Resource Timing API times, which allows remote
attackers to bypass the Same Origin Policy and obtain sensitive
information via crafted JavaScript code that leverages history.back
and performance.getEntries calls after restoring a browser session.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2015-7207.
|
| CVE-2016-1939 |
Mozilla Firefox before 44.0 stores cookies with names containing
vertical tab characters, which allows remote attackers to obtain
sensitive information by reading HTTP Cookie headers. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2015-7208.
|
| CVE-2016-1713 |
Unrestricted file upload vulnerability in the
Settings_Vtiger_CompanyDetailsSave_Action class in
modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM
6.4.0 allows remote authenticated users to execute arbitrary code by
uploading a crafted image file with an executable extension, then
accessing it via a direct request to the file in test/logo/. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2015-6000.
|
| CVE-2016-10700 |
auth_login.php in Cacti before 1.0.0 allows remote authenticated users
who use web authentication to bypass intended access restrictions by
logging in as a user not in the cacti database, because the guest user
is not considered. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2016-2313.
|
| CVE-2016-10250 |
The jp2_colr_destroy function in jp2_cod.c in JasPer before 1.900.13
allows remote attackers to cause a denial of service (NULL pointer
dereference) by leveraging incorrect cleanup of JP2 box data on error.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2016-8887.
|
| CVE-2016-10088 |
The sg implementation in the Linux kernel through 4.9 does not
properly restrict write operations in situations where the KERNEL_DS
option is set, which allows local users to read or write to arbitrary
kernel memory locations or cause a denial of service (use-after-free)
by leveraging access to a /dev/sg device, related to block/bsg.c and
drivers/scsi/sg.c. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2016-9576.
|
| CVE-2016-0376 |
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java
Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8
FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40
(7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize
classes in an AccessController doPrivileged block, which allows remote
attackers to bypass a sandbox protection mechanism and execute
arbitrary code as demonstrated by the readValue method of the
com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which
implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2013-5456.
|
| CVE-2016-0363 |
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java
Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8
FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40
(7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the
java.lang.reflect.Method class in an AccessController doPrivileged
block, which allows remote attackers to call setSecurityManager and
bypass a sandbox protection mechanism via vectors related to a Proxy
object instance implementing the java.lang.reflect.InvocationHandler
interface. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2013-3009.
|
| CVE-2016-0304 |
The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x
before 9.0.1 FP6, when a certain unsupported configuration involving
UNC share pathnames is used, allows remote attackers to bypass
authentication and possibly execute arbitrary code via unspecified
vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because
of an incomplete fix for CVE-2011-0920.
|
| CVE-2015-8834 |
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in
WordPress before 4.2.2 allows remote attackers to inject arbitrary web
script or HTML via a long comment that is improperly stored because of
limitations on the MySQL TEXT data type. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2015-3440.
|
| CVE-2015-8708 |
Stack-based buffer overflow in the conv_euctojis function in
codeconv.c in Claws Mail 3.13.1 allows remote attackers to have
unspecified impact via a crafted email, involving Japanese character
set conversion. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2015-8614.
|
| CVE-2015-8553 |
Xen allows guest OS users to obtain sensitive information from
uninitialized locations in host OS kernel memory by not enabling
memory and I/O decoding control bits. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2015-0777.
|
| CVE-2015-8472 |
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65,
1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x
before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to
cause a denial of service (application crash) or possibly have
unspecified other impact via a small bit-depth value in an IHDR (aka
image header) chunk in a PNG image. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2015-8126.
|
| CVE-2015-8113 |
Untrusted search path vulnerability in the client in Symantec Endpoint
Protection (SEP) 12.1 before 12.1-RU6-MP3 allows local users to gain
privileges via a Trojan horse DLL in a client install package. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2015-1492.
|
| CVE-2015-8078 |
Integer overflow in the index_urlfetch function in imap/index.c in
Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have
unspecified impact via vectors related to urlfetch range checks and
the section_offset variable. NOTE: this vulnerability exists because
of an incomplete fix for CVE-2015-8076.
|
| CVE-2015-8077 |
Integer overflow in the index_urlfetch function in imap/index.c in
Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have
unspecified impact via vectors related to urlfetch range checks and
the start_octet variable. NOTE: this vulnerability exists because of
an incomplete fix for CVE-2015-8076.
|
| CVE-2015-7990 |
Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the
Linux kernel before 4.3.3 allows local users to cause a denial of
service (NULL pointer dereference and system crash) or possibly have
unspecified other impact by using a socket that was not properly
bound. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2015-6937.
|
| CVE-2015-7943 |
Open redirect vulnerability in the Overlay module in Drupal 7.x before
7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and
the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to
redirect users to arbitrary web sites and conduct phishing attacks via
unspecified vectors. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2015-3233.
|
| CVE-2015-6575 |
SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I does
not properly consider integer promotion, which allows remote attackers
to execute arbitrary code or cause a denial of service (integer
overflow and memory corruption) via crafted atoms in MP4 data, aka
internal bug 20139950, a different vulnerability than CVE-2015-1538.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2014-7915, CVE-2014-7916, and/or CVE-2014-7917.
|
| CVE-2015-6305 |
Untrusted search path vulnerability in the
CMainThread::launchDownloader function in vpndownloader.exe in Cisco
AnyConnect Secure Mobility Client 2.0 through 4.1 on Windows allows
local users to gain privileges via a Trojan horse DLL in the current
working directory, as demonstrated by dbghelp.dll, aka Bug ID
CSCuv01279. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2015-4211.
|
| CVE-2015-5948 |
Race condition in SuiteCRM before 7.2.3 allows remote attackers to
execute arbitrary code. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2015-5947.
|
| CVE-2015-5914 |
The EFI component in Apple OS X before 10.11 allows physically
proximate attackers to modify firmware during the EFI update process
by inserting an Apple Ethernet Thunderbolt adapter with crafted code
in an Option ROM, aka a "Thunderstrike" issue. NOTE: this issue exists
because of an incomplete fix for CVE-2014-4498.
|
| CVE-2015-5571 |
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on
Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before
19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK &
Compiler before 19.0.0.190 do not properly restrict the SWF file
format, which allows remote attackers to conduct cross-site request
forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive
information, via a crafted OBJECT element with SWF content satisfying
the character-set requirements of a callback API. NOTE: this issue
exists because of an incomplete fix for CVE-2014-4671 and
CVE-2014-5333.
|
| CVE-2015-5470 |
The label decompression functionality in PowerDNS Recursor before
3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before
3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial
of service (CPU consumption or crash) via a request with a long name
that refers to itself. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2015-1868.
|
| CVE-2015-5325 |
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass
intended slave-to-master access restrictions by leveraging a JNLP
slave. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2014-3665.
|
| CVE-2015-5286 |
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x
before 2015.1.2 (kilo) allows remote authenticated users to bypass the
storage quota and cause a denial of service (disk consumption) by
deleting images that are being uploaded using a token that expires
during the process. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-9623.
|
| CVE-2015-5070 |
The (1) filesystem::get_wml_location function in filesystem.cpp and
(2) is_legal_file function in filesystem_boost.cpp in Battle for
Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a
case-insensitive filesystem is used, allow remote attackers to obtain
sensitive information via vectors related to inclusion of .pbl files
from WML. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2015-5069.
|
| CVE-2015-4644 |
The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka
pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x
before 5.6.10 does not validate token extraction for table names,
which might allow remote attackers to cause a denial of service (NULL
pointer dereference and application crash) via a crafted name. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2015-1352.
|
| CVE-2015-4643 |
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP
before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows
remote FTP servers to execute arbitrary code via a long reply to a
LIST command, leading to a heap-based buffer overflow. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2015-4022.
|
| CVE-2015-4544 |
EMC Documentum Content Server before 7.1P20 and 7.2.x before 7.2P04
does not properly verify authorization for dm_job object access, which
allows remote authenticated users to obtain superuser privileges via
crafted object operations. NOTE: this vulnerability exists because of
an incomplete fix for CVE-2014-4626.
|
| CVE-2015-4533 |
EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25,
7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly
check authorization after creation of an object, which allows remote
authenticated users to execute arbitrary code with super-user
privileges via a custom script. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2014-2513.
|
| CVE-2015-4532 |
EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25,
7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly
check authorization and does not properly restrict object types, which
allows remote authenticated users to run save RPC commands with
super-user privileges, and consequently execute arbitrary code, via
unspecified vectors. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-2514.
|
| CVE-2015-4531 |
EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25,
7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly
check authorization for subgroups of privileged groups, which allows
remote authenticated sysadmins to gain super-user privileges, and
bypass intended restrictions on data access and server actions, via
unspecified vectors. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-4622.
|
| CVE-2015-4530 |
Cross-site request forgery (CSRF) vulnerability in EMC Documentum
WebTop before 6.8P01, Documentum Administrator through 7.2, Documentum
Digital Assets Manager through 6.5SP6, Documentum Web Publishers
through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote
attackers to hijack the authentication of arbitrary users. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2014-2518.
|
| CVE-2015-4026 |
The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before
5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering
a \x00 character, which might allow remote attackers to bypass
intended extension restrictions and execute files with unexpected
names via a crafted first argument. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2006-7243.
|
| CVE-2015-4025 |
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9
truncates a pathname upon encountering a \x00 character in certain
situations, which allows remote attackers to bypass intended extension
restrictions and access files or directories with unexpected names via
a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or
(4) readlink. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2006-7243.
|
| CVE-2015-4020 |
RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8
does not validate the hostname when fetching gems or making API
requests, which allows remote attackers to redirect requests to
arbitrary domains via a crafted DNS SRV record with a domain that is
suffixed with the original domain name, aka a "DNS hijack attack." NOTE:
this vulnerability exists because to an incomplete fix for
CVE-2015-3900.
|
| CVE-2015-3864 |
Integer underflow in the MPEG4Extractor::parseChunk function in
MPEG4Extractor.cpp in libstagefright in mediaserver in Android before
5.1.1 LMY48M allows remote attackers to execute arbitrary code via
crafted MPEG-4 data, aka internal bug 23034759. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2015-3824.
|
| CVE-2015-3427 |
Quassel before 0.12.2 does not properly re-initialize the database
session when the PostgreSQL database is restarted, which allows remote
attackers to conduct SQL injection attacks via a \ (backslash) in a
message. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2013-4422.
|
| CVE-2015-2348 |
The move_uploaded_file implementation in
ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before
5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering
a \x00 character, which allows remote attackers to bypass intended
extension restrictions and create files with unexpected names via a
crafted second argument. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2006-7243.
|
| CVE-2015-2313 |
Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an
application invokes the totalSize method on an object reader, allows
remote peers to cause a denial of service (CPU consumption) via a
crafted small message, which triggers a "tight" for loop. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2015-2312.
|
| CVE-2015-2265 |
The remove_bad_chars function in utils/cups-browsed.c in cups-filters
before 1.0.66 allows remote IPP printers to execute arbitrary commands
via consecutive shell metacharacters in the (1) model or (2) PDL.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2014-2707.
|
| CVE-2015-1572 |
Heap-based buffer overflow in closefs.c in the libext2fs library in
e2fsprogs before 1.42.12 allows local users to execute arbitrary code
by causing a crafted block group descriptor to be marked as dirty.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2015-0247.
|
| CVE-2015-1195 |
The V2 API in OpenStack Image Registry and Delivery Service (Glance)
before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote
authenticated users to read or delete arbitrary files via a full
pathname in a filesystem: URL in the image location property. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2014-9493.
|
| CVE-2015-0284 |
Cross-site scripting (XSS) vulnerability in spacewalk-java in
Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users
to inject arbitrary web script or HTML via crafted XML data to the
XMLRPC API, involving user details. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2014-7811.
|
| CVE-2015-0231 |
Use-after-free vulnerability in the process_nested_data function in
ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before
5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute
arbitrary code via a crafted unserialize call that leverages improper
handling of duplicate numerical keys within the serialized properties
of an object. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2014-8142.
|
| CVE-2015-0226 |
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks
information about decryption failures when decrypting an encrypted key
or message data, which makes it easier for remote attackers to recover
the plaintext form of a symmetric key via a series of crafted
messages. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2011-2487.
|
| CVE-2015-0224 |
qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause
a denial of service (daemon crash) via a crafted protocol sequence
set. NOTE: this vulnerability exists because of an incomplete fix for
CVE-2015-0203.
|
| CVE-2014-9686 |
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote
attackers with control of a sub-domain belonging to a victim domain to
cause a denial of service via the 'url' parameter to
plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists because
of an incomplete fix for CVE-2013-7428.
|
| CVE-2014-9659 |
cff/cf2intrp.c in the CFF CharString interpreter in FreeType before
2.5.4 proceeds with additional hints after the hint mask has been
computed, which allows remote attackers to execute arbitrary code or
cause a denial of service (stack-based buffer overflow) via a crafted
OpenType font. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-2240.
|
| CVE-2014-8554 |
SQL injection vulnerability in the mc_project_get_attachments function
in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remote
attackers to execute arbitrary SQL commands via the project_id
parameter. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2014-1609.
|
| CVE-2014-8481 |
The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem
in the Linux kernel before 3.18-rc2 does not properly handle invalid
instructions, which allows guest OS users to cause a denial of service
(NULL pointer dereference and host OS crash) via a crafted application
that triggers (1) an improperly fetched instruction or (2) an
instruction that occupies too many bytes. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2014-8480.
|
| CVE-2014-8106 |
Heap-based buffer overflow in the Cirrus VGA emulator
(hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest
users to execute arbitrary code via vectors related to blit regions.
NOTE: this vulnerability exists because an incomplete fix for
CVE-2007-1320.
|
| CVE-2014-8090 |
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x
before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote
attackers to cause a denial of service (CPU and memory consumption) a
crafted XML document containing an empty string in an entity that is
used in a large number of nested entity references, aka an XML Entity
Expansion (XEE) attack. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2013-1821 and CVE-2014-8080.
|
| CVE-2014-7824 |
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and
1.9.x before 1.9.2 allows local users to cause a denial of service
(prevention of new connections and connection drop) by queuing the
maximum number of file descriptors. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2014-3636.1.
|
| CVE-2014-7266 |
Algorithmic complexity vulnerability in Cybozu Remote Service Manager
through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a
denial of service (CPU consumption) via vectors that trigger colliding
hash-table keys. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-1983.
|
| CVE-2014-7169 |
GNU Bash through 4.3 bash43-025 processes trailing strings after
certain malformed function definitions in the values of environment
variables, which allows remote attackers to write to files or possibly
have unknown other impact via a crafted environment, as demonstrated
by vectors involving the ForceCommand feature in OpenSSH sshd, the
mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts
executed by unspecified DHCP clients, and other situations in which
setting the environment occurs across a privilege boundary from Bash
execution. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2014-6271.
|
| CVE-2014-6278 |
GNU Bash through 4.3 bash43-026 does not properly parse function
definitions in the values of environment variables, which allows
remote attackers to execute arbitrary commands via a crafted
environment, as demonstrated by vectors involving the ForceCommand
feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the
Apache HTTP Server, scripts executed by unspecified DHCP clients, and
other situations in which setting the environment occurs across a
privilege boundary from Bash execution. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169,
and CVE-2014-6277.
|
| CVE-2014-6277 |
GNU Bash through 4.3 bash43-026 does not properly parse function
definitions in the values of environment variables, which allows
remote attackers to execute arbitrary code or cause a denial of
service (uninitialized memory access, and untrusted-pointer read and
write operations) via a crafted environment, as demonstrated by
vectors involving the ForceCommand feature in OpenSSH sshd, the
mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts
executed by unspecified DHCP clients, and other situations in which
setting the environment occurs across a privilege boundary from Bash
execution. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2014-6271 and CVE-2014-7169.
|
| CVE-2014-5447 |
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions
(644) for config.php, which allows local users to obtain sensitive
information by reading the PHP session files. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2014-0103.
|
| CVE-2014-5333 |
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on
Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before
14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe
AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before
14.0.0.178 do not properly restrict the SWF file format, which allows
remote attackers to conduct cross-site request forgery (CSRF) attacks
against JSONP endpoints, and obtain sensitive information, via a
crafted OBJECT element with SWF content satisfying the character-set
requirements of a callback API, in conjunction with a manipulation
involving a '$' (dollar sign) or '(' (open parenthesis) character.
NOTE: this issue exists because of an incomplete fix for
CVE-2014-4671.
|
| CVE-2014-5029 |
The web interface in CUPS 1.7.4 allows local users in the lp group to
read arbitrary files via a symlink attack on a file in
/var/cache/cups/rss/ and language[0] set to null. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2014-3537.
|
| CVE-2014-4703 |
lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain
sensitive information via a symlink attack on the configuration file
in the extra-opts flag. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-4701.
|
| CVE-2014-4626 |
EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18,
7.0 before P16, and 7.1 before P09 allows remote authenticated users
to gain privileges by (1) placing a command in a dm_job object and
setting this object's owner to a privileged user or placing a rename
action in a dm_job_request object and waiting for a (2) dm_UserRename
or (3) dm_GroupRename service task, aka ESA-2014-105. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2014-2515.
|
| CVE-2014-4336 |
The generate_local_queue function in utils/cups-browsed.c in
cups-browsed in cups-filters before 1.0.53 allows remote IPP printers
to execute arbitrary commands via shell metacharacters in the host
name. NOTE: this vulnerability exists because of an incomplete fix for
CVE-2014-2707.
|
| CVE-2014-3977 |
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to
overwrite arbitrary files via a symlink attack on a temporary file.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2012-2179.
|
| CVE-2014-3887 |
Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk
with firmware before 1.05e1-2.0.5 allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors. NOTE:
This vulnerability exists because of an incomplete fix for
CVE-2013-4713.
|
| CVE-2014-3683 |
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and
sysklogd 1.5 and earlier allows remote attackers to cause a denial of
service (crash) via a large priority (PRI) value. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2014-3634.
|
| CVE-2014-3608 |
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows
remote authenticated users to bypass the quota limit and cause a
denial of service (resource consumption) by putting the VM into the
rescue state, suspending it, which puts into an ERROR state, and then
deleting the image. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-2573.
|
| CVE-2014-3597 |
Multiple buffer overflows in the php_parserr function in
ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow
remote DNS servers to cause a denial of service (application crash) or
possibly execute arbitrary code via a crafted DNS record, related to
the dns_get_record function and the dn_expand function. NOTE: this
issue exists because of an incomplete fix for CVE-2014-4049.
|
| CVE-2014-3596 |
The getCN function in Apache Axis 1.4 and earlier does not properly
verify that the server hostname matches a domain name in the subject's
Common Name (CN) or subjectAltName field of the X.509 certificate,
which allows man-in-the-middle attackers to spoof SSL servers via a
certificate with a subject that specifies a common name in a field
that is not the CN field. NOTE: this issue exists because of an
incomplete fix for CVE-2012-5784.
|
| CVE-2014-3587 |
Integer overflow in the cdf_read_property_info function in cdf.c in
file through 5.19, as used in the Fileinfo component in PHP before
5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a
denial of service (application crash) via a crafted CDF file. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2012-1571.
|
| CVE-2014-3538 |
file before 5.19 does not properly restrict the amount of data read
during a regex search, which allows remote attackers to cause a denial
of service (CPU consumption) via a crafted file that triggers
backtracking during processing of an awk rule. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2013-7345.
|
| CVE-2014-3490 |
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red
Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not
disable external entities when the
resteasy.document.expand.entity.references parameter is set to false,
which allows remote attackers to read arbitrary files and have other
unspecified impact via unspecified vectors, related to an XML External
Entity (XXE) issue. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2012-0818.
|
| CVE-2014-3464 |
The EJB invocation handler implementation in Red Hat JBossWS, as used
in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does
not properly enforce the method level restrictions for outbound
messages, which allows remote authenticated users to access otherwise
restricted JAX-WS handlers by leveraging permissions to the EJB class.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2013-2133.
|
| CVE-2014-2683 |
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6
and 2.2.x before 2.2.6, ZendOpenId, ZendRest,
ZendService_AudioScrobbler, ZendService_Nirvanix,
ZendService_SlideShare, ZendService_Technorati, and
ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before
2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to
cause a denial of service (CPU consumption) via (1) recursive or (2)
circular references in an XML entity definition in an XML DOCTYPE
declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this
issue exists because of an incomplete fix for CVE-2012-6532.
|
| CVE-2014-2682 |
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6
and 2.2.x before 2.2.6, ZendOpenId, ZendRest,
ZendService_AudioScrobbler, ZendService_Nirvanix,
ZendService_SlideShare, ZendService_Technorati, and
ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before
2.0.3, and ZendService_Api before 1.0.0, when PHP-FPM is used, does
not properly share the libxml_disable_entity_loader setting between
threads, which might allow remote attackers to conduct XML External
Entity (XXE) attacks via an XML external entity declaration in
conjunction with an entity reference. NOTE: this issue exists because
of an incomplete fix for CVE-2012-5657.
|
| CVE-2014-2681 |
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6
and 2.2.x before 2.2.6, ZendOpenId, ZendRest,
ZendService_AudioScrobbler, ZendService_Nirvanix,
ZendService_SlideShare, ZendService_Technorati, and
ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before
2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to read
arbitrary files, send HTTP requests to intranet servers, and possibly
cause a denial of service (CPU and memory consumption) via an XML
External Entity (XXE) attack. NOTE: this issue exists because of an
incomplete fix for CVE-2012-5657.
|
| CVE-2014-2058 |
BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows
remote authenticated users to bypass access restrictions and execute
arbitrary jobs by configuring a job to trigger another job. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2013-7330.
|
| CVE-2014-2037 |
Openswan 2.6.40 allows remote attackers to cause a denial of service
(NULL pointer dereference and IKE daemon restart) via IKEv2 packets
that lack expected payloads. NOTE: this vulnerability exists because
of an incomplete fix for CVE 2013-6466.
|
| CVE-2014-1929 |
python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to
have an unspecified impact via vectors related to "option injection
through positional arguments." NOTE: this vulnerability exists because
of an incomplete fix for CVE-2013-7323.
|
| CVE-2014-1928 |
The shell_quote function in python-gnupg 0.3.5 does not properly
escape characters, which allows context-dependent attackers to execute
arbitrary code via shell metacharacters in unspecified vectors, as
demonstrated using "\" (backslash) characters to form multi-command
sequences, a different vulnerability than CVE-2014-1927. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2013-7323.
|
| CVE-2014-1927 |
The shell_quote function in python-gnupg 0.3.5 does not properly quote
strings, which allows context-dependent attackers to execute arbitrary
code via shell metacharacters in unspecified vectors, as demonstrated
using "$(" command-substitution sequences, a different vulnerability
than CVE-2014-1928. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2013-7323.
|
| CVE-2014-1832 |
Phusion Passenger 4.0.37 allows local users to write to certain files
and directories via a symlink attack on (1) control_process.pid or a
(2) generation-* file. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-1831.
|
| CVE-2014-1566 |
Mozilla Firefox before 31.1 on Android does not properly restrict
copying of local files onto the SD card during processing of file:
URLs, which allows attackers to obtain sensitive information from the
Firefox profile directory via a crafted application. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2014-1515.
|
| CVE-2014-1226 |
The pipe_init_terminal function in main.c in s3dvt allows local users
to gain privileges by leveraging setuid permissions and usage of bash
4.3 and earlier. NOTE: This vulnerability exists because of an
incomplete fix for CVE-2013-6876.
|
| CVE-2014-0994 |
Heap-based buffer overflow in the ReadDIB function in the
Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component
Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++
Builder XE6 20.0.15596.9843 allows context-dependent attackers to
execute arbitrary code via the BITMAPINFOHEADER.biClrUsed field in a
BMP file. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2014-0993.
|
| CVE-2014-0116 |
CookieInterceptor in Apache Struts 2.x before 2.3.16.3, when a
wildcard cookiesName value is used, does not properly restrict access
to the getClass method, which allows remote attackers to "manipulate"
the ClassLoader and modify session state via a crafted request. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2014-0113.
|
| CVE-2014-0113 |
CookieInterceptor in Apache Struts before 2.3.16.2, when a wildcard
cookiesName value is used, does not properly restrict access to the
getClass method, which allows remote attackers to "manipulate" the
ClassLoader and execute arbitrary code via a crafted request. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2014-0094.
|
| CVE-2014-0112 |
ParametersInterceptor in Apache Struts before 2.3.16.2 does not
properly restrict access to the getClass method, which allows remote
attackers to "manipulate" the ClassLoader and execute arbitrary code
via a crafted request. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2014-0094.
|
| CVE-2014-0054 |
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring
Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable
external entity resolution, which allows remote attackers to read
arbitrary files, cause a denial of service, and conduct CSRF attacks
via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2013-4152,
CVE-2013-7315, and CVE-2013-6429.
|
| CVE-2014-0012 |
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create
temporary directories, which allows local users to gain privileges by
pre-creating a temporary directory with a user's uid. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2014-1402.
|
| CVE-2013-7385 |
LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator
password in plaintext in Javascript code that is generated by
lz/mobile/chat.php, which allows remote attackers to obtain sensitive
information and gain privileges by accessing the loginName and
loginPassword variables using an independent cross-site scripting
(XSS) attack. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2013-7033.
|
| CVE-2013-7343 |
Cross-site scripting (XSS) vulnerability in flowplayer.swf in the
Flash fallback feature in Flowplayer HTML5 5.4.3 allows remote
attackers to inject arbitrary web script or HTML by using URL encoding
within the callback parameter name. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2013-7342.
|
| CVE-2013-7110 |
Transifex command-line client before 0.10 does not validate X.509
certificates for data transfer connections, which allows
man-in-the-middle attackers to spoof a Transifex server via an
arbitrary certificate. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2013-2073.
|
| CVE-2013-7040 |
Python 2.7 before 3.4 only uses the last eight bits of the prefix to
randomize hash values, which causes it to compute hash values without
restricting the ability to trigger hash collisions predictably and
makes it easier for context-dependent attackers to cause a denial of
service (CPU consumption) via crafted input to an application that
maintains a hash table. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2012-1150.
|
| CVE-2013-6934 |
The parseRTSPRequestString function in Live Networks Live555 Streaming
Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote
attackers to cause a denial of service (crash) and possibly execute
arbitrary code via a space character at the beginning of an RTSP
message, which triggers an integer underflow, infinite loop, and
buffer overflow. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2013-6933.
|
| CVE-2013-6799 |
Apple Mac OS X 10.9 allows local users to cause a denial of service
(memory corruption or panic) by creating a hard link to a directory.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2010-0105.
|
| CVE-2013-6486 |
gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted
remote attackers to execute arbitrary programs via a message
containing a file: URL that is improperly handled during construction
of an explorer.exe command. NOTE: this vulnerability exists because of
an incomplete fix for CVE-2011-3185.
|
| CVE-2013-6417 |
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before
3.2.16 and 4.x before 4.0.2 does not properly consider differences in
parameter handling between the Active Record component and the JSON
implementation, which allows remote attackers to bypass intended
database-query restrictions and perform NULL checks or trigger missing
WHERE clauses via a crafted request that leverages (1) third-party
Rack middleware or (2) custom Rack middleware. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2013-0155.
|
| CVE-2013-6408 |
The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does
not properly use the EmptyEntityResolver, which allows remote
attackers to have an unspecified impact via XML data containing an
external entity declaration in conjunction with an entity reference,
related to an XML External Entity (XXE) issue. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2013-6407.
|
| CVE-2013-4458 |
Stack-based buffer overflow in the getaddrinfo function in
sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18
and earlier allows remote attackers to cause a denial of service
(crash) via a (1) hostname or (2) IP address that triggers a large
number of AF_INET6 address results. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2013-1914.
|
| CVE-2013-4322 |
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before
8.0.0-RC10 processes chunked transfer coding without properly handling
(1) a large total amount of chunked data or (2) whitespace characters
in an HTTP header value within a trailer field, which allows remote
attackers to cause a denial of service by streaming data. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-3544.
|
| CVE-2013-4321 |
The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x
before 6.1.4 allows remote authenticated editors to execute arbitrary
PHP code via unspecified characters in the file extension when
renaming a file. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2013-4250.
|
| CVE-2013-4286 |
Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before
8.0.0-RC3, when an HTTP connector or AJP connector is used, does not
properly handle certain inconsistent HTTP request headers, which
allows remote attackers to trigger incorrect identification of a
request's length and conduct request-smuggling attacks via (1)
multiple Content-Length headers or (2) a Content-Length header and a
"Transfer-Encoding: chunked" header. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2005-2090.
|
| CVE-2013-3664 |
Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689)
allows remote attackers to execute arbitrary code via a crafted color
palette table in a MAC Pict texture, which triggers an out-of-bounds
stack write. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2013-3662. NOTE: this issue was SPLIT due to different
affected products and codebases (ADT1); CVE-2013-7388 has been
assigned to the paintlib issue.
|
| CVE-2013-1799 |
Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before
3.7.91, does not properly validate SSL certificates when creating
accounts for providers who use the libsoup library, which allows
man-in-the-middle attackers to obtain sensitive information such as
credentials by sniffing the network. NOTE: this issue exists because
of an incomplete fix for CVE-2013-0240.
|
| CVE-2013-1743 |
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in
Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1
allow remote attackers to inject arbitrary web script or HTML via a
field value that is not properly handled during construction of a
tabular report, as demonstrated by the (1) summary or (2) real name
field. NOTE: this issue exists because of an incomplete fix for
CVE-2012-4189.
|
| CVE-2013-1715 |
Multiple untrusted search path vulnerabilities in the (1) full
installer and (2) stub installer in Mozilla Firefox before 23.0 on
Windows allow local users to gain privileges via a Trojan horse DLL in
the default downloads directory. NOTE: this issue exists because of an
incomplete fix for CVE-2012-4206.
|
| CVE-2013-0198 |
Dnsmasq before 2.66test2, when used with certain libvirt
configurations, replies to queries from prohibited interfaces, which
allows remote attackers to cause a denial of service (traffic
amplification) via spoofed TCP based DNS queries. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-3411.
|
| CVE-2012-6696 |
inspircd in Debian before 2.0.7 does not properly handle unsigned
integers. NOTE: This vulnerability exists because of an incomplete fix
to CVE-2012-1836.
|
| CVE-2012-6153 |
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient
before 4.2.3 does not properly verify that the server hostname matches
a domain name in the subject's Common Name (CN) or subjectAltName
field of the X.509 certificate, which allows man-in-the-middle
attackers to spoof SSL servers via a certificate with a subject that
specifies a common name in a field that is not the CN field. NOTE:
this issue exists because of an incomplete fix for CVE-2012-5783.
|
| CVE-2012-5920 |
Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT)
2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1
and possibly other products, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors. NOTE: this
issue exists because of an incomplete fix for CVE-2012-4563.
|
| CVE-2012-5482 |
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex
(2012.1) allows remote authenticated users to delete arbitrary
non-protected images via an image deletion request. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-4573.
|
| CVE-2012-5453 |
SQL injection vulnerability in user/index_inline_editor_submit.php in
ATutor AContent 1.2-1 allows remote authenticated users to execute
arbitrary SQL commands via the field parameter. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-5167.
|
| CVE-2012-5318 |
Unrestricted file upload vulnerability in
uploadify/scripts/uploadify.php in the Kish Guest Posting plugin 1.2
for WordPress allows remote attackers to execute arbitrary code by
uploading a file with a double extension, then accessing it via a
direct request to the file in the directory specified by the folder
parameter. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2012-1125.
|
| CVE-2012-4359 |
Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA
before 2.07.18 do not validate the return value of the realloc
function, which allows remote attackers to cause a denial of service
(invalid 0x00 write operation and daemon crash) or possibly have
unspecified other impact via a port-46824 TCP packet with a crafted
negative integer after the opcode. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2012-4358.
|
| CVE-2012-4355 |
TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and
Winlog Lite SCADA before 2.07.18 allows remote attackers to execute
arbitrary code via a port-46824 TCP packet with a crafted negative
integer after the opcode, triggering incorrect function-pointer
processing that can lead to a buffer overflow. NOTE: some of these
details are obtained from third party information. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-4354.
|
| CVE-2012-3447 |
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2
and Folsom before Folsom-3 allows remote authenticated users to
overwrite arbitrary files via a symlink attack on a file in an image
that uses a symlink that is only readable by root. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-3361.
|
| CVE-2012-2986 |
lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN
Appliance allows remote authenticated users to execute arbitrary
commands via shell metacharacters in the (1) first, (2) third, or (3)
fourth parameter. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2012-4361.
|
| CVE-2012-2751 |
ModSecurity before 2.6.6, when used with PHP, does not properly handle
single quotes not at the beginning of a request parameter value in the
Content-Disposition field of a request with a multipart/form-data
Content-Type header, which allows remote attackers to bypass filtering
rules and perform other attacks such as cross-site scripting (XSS)
attacks. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2009-5031.
|
| CVE-2012-2375 |
The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4
implementation in the Linux kernel before 3.3.2 uses an incorrect
length variable during a copy operation, which allows remote NFS
servers to cause a denial of service (OOPS) by sending an excessive
number of bitmap words in an FATTR4_ACL reply. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2011-4131.
|
| CVE-2012-2336 |
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when
configured as a CGI script (aka php-cgi), does not properly handle
query strings that lack an = (equals sign) character, which allows
remote attackers to cause a denial of service (resource consumption)
by placing command-line options in the query string, related to lack
of skipping a certain php_getopt for the 'T' case. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-1823.
|
| CVE-2012-2311 |
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when
configured as a CGI script (aka php-cgi), does not properly handle
query strings that contain a %3D sequence but no = (equals sign)
character, which allows remote attackers to execute arbitrary code by
placing command-line options in the query string, related to lack of
skipping a certain php_getopt for the 'd' case. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-1823.
|
| CVE-2012-2131 |
Multiple integer signedness errors in crypto/buffer/buffer.c in
OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow
attacks, and cause a denial of service (memory corruption) or possibly
have unspecified other impact, via crafted DER data, as demonstrated
by an X.509 certificate or an RSA public key. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2012-2110.
|
| CVE-2012-2100 |
The ext4_fill_flex_info function in fs/ext4/super.c in the Linux
kernel before 3.2.2, on the x86 platform and unspecified other
platforms, allows user-assisted remote attackers to trigger
inconsistent filesystem-groups data and possibly cause a denial of
service via a malformed ext4 filesystem containing a super block with
a large FLEX_BG group size (aka s_log_groups_per_flex value). NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2009-4307.
|
| CVE-2012-1610 |
Integer overflow in the GetEXIFProperty function in magick/property.c
in ImageMagick before 6.7.6-4 allows remote attackers to cause a
denial of service (out-of-bounds read) via a large component count for
certain EXIF tags in a JPEG image. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2012-0259.
|
| CVE-2012-1235 |
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin
WebAccess 7.0 allows remote authenticated users to hijack the
authentication of unspecified victims via unknown vectors. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-0235.
|
| CVE-2012-1234 |
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows
remote authenticated users to execute arbitrary SQL commands via a
malformed URL. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2012-0234.
|
| CVE-2012-1186 |
Integer overflow in the SyncImageProfiles function in profile.c in
ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a
denial of service (infinite loop) via crafted IOP tag offsets in the
IFD in an image. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2012-0248.
|
| CVE-2012-1185 |
Multiple integer overflows in (1) magick/profile.c or (2)
magick/property.c in ImageMagick 6.7.5 and earlier allow remote
attackers to cause a denial of service (memory corruption) and
possibly execute arbitrary code via crafted offset value in the
ResolutionUnit tag in the EXIF IFD0 of an image. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2012-0247.
|
| CVE-2012-0954 |
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the
apt-key net-update to import keyrings, relies on GnuPG argument order
and does not check GPG subkeys, which might allow remote attackers to
install altered packages via a man-in-the-middle (MITM) attack. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2012-3587.
|
| CVE-2012-0950 |
The Apport hook (DistUpgradeApport.py) in Update Manager, as used by
Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade
directory when reporting bugs to Launchpad, which allows remote
attackers to read repository credentials by viewing a public bug
report. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2012-0949.
|
| CVE-2012-0859 |
The render_line function in the vorbis codec (vorbis.c) in libavcodec
in FFmpeg before 0.9.1 allows remote attackers to cause a denial of
service (application crash) and possibly execute arbitrary code via a
crafted Vorbis file, related to a large multiplier. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2011-3893.
|
| CVE-2011-5055 |
MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without
properly restricting the ability to trigger hash collisions
predictably, which allows remote attackers to cause a denial of
service (CPU consumption) by sending many crafted queries with the
Recursion Desired (RD) bit set. NOTE: this issue exists because of an
incomplete fix for CVE-2012-0024.
|
| CVE-2011-4348 |
Race condition in the sctp_rcv function in net/sctp/input.c in the
Linux kernel before 2.6.29 allows remote attackers to cause a denial
of service (system hang) via SCTP packets. NOTE: in some environments,
this issue exists because of an incomplete fix for CVE-2011-2482.
|
| CVE-2011-4317 |
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42,
2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision
1179239 patch is in place, does not properly interact with use of (1)
RewriteRule and (2) ProxyPassMatch pattern matches for configuration
of a reverse proxy, which allows remote attackers to send requests to
intranet servers via a malformed URI containing an @ (at sign)
character and a : (colon) character in invalid positions. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2011-3368.
|
| CVE-2011-3639 |
The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64
and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place,
does not properly interact with use of (1) RewriteRule and (2)
ProxyPassMatch pattern matches for configuration of a reverse proxy,
which allows remote attackers to send requests to intranet servers by
using the HTTP/0.9 protocol with a malformed URI containing an initial
@ (at sign) character. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2011-3368.
|
| CVE-2011-2724 |
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs
in Samba 3.5.10 and earlier does not properly verify that the (1)
device name and (2) mountpoint strings are composed of valid
characters, which allows local users to cause a denial of service
(mtab corruption) via a crafted string. NOTE: this vulnerability
exists because of an incorrect fix for CVE-2010-0547.
|
| CVE-2011-2710 |
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before
1.7.0 allow remote attackers to inject arbitrary web script or HTML
via (1) the URI to includes/application.php, reachable through
index.php; and, when Internet Explorer or Konqueror is used, (2) allow
remote attackers to inject arbitrary web script or HTML via the
searchword parameter in a search action to index.php in the com_search
component. NOTE: vector 2 exists because of an incomplete fix for
CVE-2011-2509.5.
|
| CVE-2011-2383 |
Microsoft Internet Explorer 9 and earlier does not properly restrict
cross-zone drag-and-drop actions, which allows user-assisted remote
attackers to read cookie files via vectors involving an IFRAME element
with a SRC attribute containing an http: URL that redirects to a file:
URL, as demonstrated by a Facebook game, related to a "cookiejacking"
issue, aka "Drag and Drop Information Disclosure Vulnerability." NOTE:
this vulnerability exists because of an incomplete fix in the Internet
Explorer 9 release.
|
| CVE-2011-2196 |
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as
distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and
5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP)
4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1,
does not properly restrict use of Expression Language (EL) statements
in FacesMessages during page exception handling, which allows remote
attackers to execute arbitrary Java code via a crafted URL to an
application. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2011-1484.
|
| CVE-2011-2182 |
The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel
before 2.6.39.1 does not properly handle memory allocation for
non-initial fragments, which might allow local users to conduct buffer
overflow attacks, and gain privileges or obtain sensitive information,
via a crafted LDM partition table. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2011-1017.
|
| CVE-2011-2082 |
The vulnerable-passwords script in Best Practical Solutions RT 3.x
before 3.8.12 and 4.x before 4.0.6 does not update the password-hash
algorithm for disabled user accounts, which makes it easier for
context-dependent attackers to determine cleartext passwords, and
possibly use these passwords after accounts are re-enabled, via a
brute-force attack on the database. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2011-0009.
|
| CVE-2011-1782 |
Heap-based buffer overflow in the read_channel_data function in
file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows
remote attackers to cause a denial of service (application crash) or
possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE
compression) image file that begins a long run count at the end of the
image. NOTE: some of these details are obtained from third party
information. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2010-4543.
|
| CVE-2011-1765 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5,
when Internet Explorer 6 or earlier is used, allows remote attackers
to inject arbitrary web script or HTML via an uploaded file accessed
with a dangerous extension such as .shtml at the end of the query
string, in conjunction with a modified URI path that has a %2E
sequence in place of the . (dot) character. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2011-1578 and
CVE-2011-1587.
|
| CVE-2011-1682 |
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList
2.10.13 and earlier allow remote attackers to hijack the
authentication of administrators for requests that (1) create a list
or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue
exists because of an incomplete fix for CVE-2011-0748. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2011-1587 |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.4,
when Internet Explorer 6 or earlier is used, allows remote attackers
to inject arbitrary web script or HTML via an uploaded file accessed
with a dangerous extension such as .html located before a ? (question
mark) in a query string, in conjunction with a modified URI path that
has a %2E sequence in place of the . (dot) character. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2011-1578.
|
| CVE-2011-1586 |
Directory traversal vulnerability in the
KGetMetalink::File::isValidNameAttr function in
ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier
allows remote attackers to create arbitrary files via a .. (dot dot)
in the name attribute of a file element in a metalink file. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2010-1000.
|
| CVE-2011-1582 |
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a
servlet without following security constraints that have been
configured through annotations, which allows remote attackers to
bypass intended access restrictions via HTTP requests. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2011-1088,
CVE-2011-1183, and CVE-2011-1419.
|
| CVE-2011-1419 |
Apache Tomcat 7.x before 7.0.11, when web.xml has no security
constraints, does not follow ServletSecurity annotations, which allows
remote attackers to bypass intended access restrictions via HTTP
requests to a web application. NOTE: this vulnerability exists because
of an incomplete fix for CVE-2011-1088.
|
| CVE-2011-1362 |
Cross-site scripting (XSS) vulnerability in the Installation
Verification Test (IVT) application in the Install component in IBM
WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before
7.0.0.19 allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors. NOTE: this vulnerability exists because
of an incomplete fix for CVE-2011-1308.
|
| CVE-2011-1144 |
The installer in PEAR 1.9.2 and earlier allows local users to
overwrite arbitrary files via a symlink attack on the package.xml
file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and
(4) pear-build-download directories. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2011-1072.
|
| CVE-2011-1021 |
drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local
users to modify arbitrary kernel memory locations by leveraging root
privileges to write to the /sys/kernel/debug/acpi/custom_method file.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2010-4347.
|
| CVE-2010-4805 |
The socket implementation in net/core/sock.c in the Linux kernel
before 2.6.35 does not properly manage a backlog of received packets,
which allows remote attackers to cause a denial of service by sending
a large amount of network traffic, related to the sk_add_backlog
function and the sk_rmem_alloc socket field. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2010-4251.
|
| CVE-2010-4668 |
The blk_rq_map_user_iov function in block/blk-map.c in the Linux
kernel before 2.6.37-rc7 allows local users to cause a denial of
service (panic) via a zero-length I/O request in a device ioctl to a
SCSI device, related to an unaligned map. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2010-4163.
|
| CVE-2010-4411 |
Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote
attackers to inject arbitrary HTTP headers and conduct HTTP response
splitting attacks via unknown vectors. NOTE: this issue exists because
of an incomplete fix for CVE-2010-2761.
|
| CVE-2010-3773 |
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey
before 2.0.11, when the XMLHttpRequestSpy module in the Firebug add-on
is used, does not properly handle interaction between the
XMLHttpRequestSpy object and chrome privileged objects, which allows
remote attackers to execute arbitrary JavaScript via a crafted HTTP
response. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2010-0179.
|
| CVE-2010-3477 |
The tcf_act_police_dump function in net/sched/act_police.c in the
actions implementation in the network queueing functionality in the
Linux kernel before 2.6.36-rc4 does not properly initialize certain
structure members, which allows local users to obtain potentially
sensitive information from kernel memory via vectors involving a dump
operation. NOTE: this vulnerability exists because of an incomplete
fix for CVE-2010-2942.
|
| CVE-2010-3431 |
The privilege-dropping implementation in the (1) pam_env and (2)
pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the
return value of the setfsuid system call, which might allow local
users to obtain sensitive information by leveraging an unintended uid,
as demonstrated by a symlink attack on the .pam_environment file in a
user's home directory. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2010-3435.
|
| CVE-2010-3430 |
The privilege-dropping implementation in the (1) pam_env and (2)
pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the
required setfsgid and setgroups system calls, which might allow local
users to obtain sensitive information by leveraging unintended group
permissions, as demonstrated by a symlink attack on the
.pam_environment file in a user's home directory. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2010-3435.
|
| CVE-2010-2971 |
loaders/load_it.c in libmikmod, possibly 3.1.12, does not properly
account for the larger size of name##env relative to name##tick and
name##node, which allows remote attackers to trigger a buffer
over-read and possibly have unspecified other impact via a crafted
Impulse Tracker file, a related issue to CVE-2010-2546. NOTE: this
issue exists because of an incomplete fix for CVE-2009-3995.
|
| CVE-2010-2950 |
Format string vulnerability in stream.c in the phar extension in PHP
5.3.x through 5.3.3 allows context-dependent attackers to obtain
sensitive information (memory contents) and possibly execute arbitrary
code via a crafted phar:// URI that is not properly handled by the
phar_stream_flush function, leading to errors in the
php_stream_wrapper_log_error function. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2010-2094.
|
| CVE-2010-2760 |
Use-after-free vulnerability in the nsTreeSelection function in
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird
before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might
allow remote attackers to execute arbitrary code via vectors involving
a XUL tree selection, related to a "dangling pointer vulnerability."
NOTE: this issue exists because of an incomplete fix for
CVE-2010-2753.
|
| CVE-2010-2629 |
The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02
and the Application Control Engine (ACE) 4710 with software A2(3.0) do
not properly handle LF header terminators in situations where the GET
line is terminated by CRLF, which allows remote attackers to conduct
HTTP request smuggling attacks and possibly bypass intended header
insertions via crafted header data, as demonstrated by an LF character
between the ClientCert-Subject and ClientCert-Subject-CN headers.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2010-1576.
|
| CVE-2010-2546 |
Multiple heap-based buffer overflows in loaders/load_it.c in
libmikmod, possibly 3.1.12, might allow remote attackers to execute
arbitrary code via (1) crafted samples or (2) crafted instrument
definitions in an Impulse Tracker file, related to panpts, pitpts, and
IT_ProcessEnvelope. NOTE: some of these details are obtained from
third party information. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2009-3995.
|
| CVE-2010-2322 |
Absolute path traversal vulnerability in the extract_jar function in
jartool.c in FastJar 0.98 allows remote attackers to create or
overwrite arbitrary files via a full pathname for a file within a .jar
archive, a related issue to CVE-2010-0831. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2006-3619.
|
| CVE-2010-1449 |
Integer overflow in rgbimgmodule.c in the rgbimg module in Python 2.5
allows remote attackers to have an unspecified impact via a large
image that triggers a buffer overflow. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2008-3143.12.
|
| CVE-2010-0831 |
Directory traversal vulnerability in the extract_jar function in
jartool.c in FastJar 0.98 allows remote attackers to create or
overwrite arbitrary files via a .. (dot dot) in a non-initial pathname
component in a filename within a .jar archive, a related issue to
CVE-2005-1080. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2006-3619.
|
| CVE-2010-0302 |
Use-after-free vulnerability in the abstract file-descriptor handling
interface in the cupsdDoSelect function in scheduler/select.c in the
scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used,
allows remote attackers to cause a denial of service (daemon crash or
hang) via a client disconnection during listing of a large number of
print jobs, related to improperly maintaining a reference count. NOTE:
some of these details are obtained from third party information. NOTE:
this vulnerability exists because of an incomplete fix for
CVE-2009-3553.
|
| CVE-2010-0290 |
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before
9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta,
with DNSSEC validation enabled and checking disabled (CD), allows
remote attackers to conduct DNS cache poisoning attacks by receiving a
recursive client query and sending a response that contains (1) CNAME
or (2) DNAME records, which do not have the intended validation before
caching, aka Bug 20737. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2009-4022.
|
| CVE-2010-0171 |
Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x
before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3
allow remote attackers to perform cross-origin keystroke capture, and
possibly conduct cross-site scripting (XSS) attacks, by using the
addEventListener and setTimeout functions in conjunction with a
wrapped object. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2007-3736.
|
| CVE-2009-4030 |
MySQL 5.1.x before 5.1.41 allows local users to bypass certain
privilege checks by calling CREATE TABLE on a MyISAM table with
modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are
originally associated with pathnames without symlinks, and that can
point to tables created at a future time at which a pathname is
modified to contain a symlink to a subdirectory of the MySQL data home
directory, related to incorrect calculation of the
mysql_unpacked_real_data_home value. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
|
| CVE-2009-3951 |
Unspecified vulnerability in the Flash Player ActiveX control in Adobe
Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows
allows remote attackers to obtain the names of local files via unknown
vectors. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2008-4820.
|
| CVE-2009-3612 |
The tcf_fill_node function in net/sched/cls_api.c in the netlink
subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6
and earlier, does not initialize a certain tcm__pad2 structure member,
which might allow local users to obtain sensitive information from
kernel memory via unspecified vectors. NOTE: this issue exists because
of an incomplete fix for CVE-2005-4881.
|
| CVE-2009-3603 |
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf
3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote
attackers to execute arbitrary code via a crafted PDF document that
triggers a heap-based buffer overflow. NOTE: some of these details are
obtained from third party information. NOTE: this issue reportedly
exists because of an incomplete fix for CVE-2009-1188.
|
| CVE-2009-3164 |
Unspecified vulnerability in the IPv6 networking stack in Sun Solaris
10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_122,
when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used,
allows remote attackers to cause a denial of service (panic) via
vectors involving jumbo frames. NOTE: this issue exists because of an
incomplete fix for CVE-2009-2136.
|
| CVE-2009-2694 |
The msn_slplink_process_msg function in
libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin
(formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) by sending multiple
crafted SLP (aka MSNSLP) messages to trigger an overwrite of an
arbitrary memory location. NOTE: this issue reportedly exists because
of an incomplete fix for CVE-2009-1376.
|
| CVE-2009-2281 |
Multiple heap-based buffer underflows in the readPostBody function in
cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before
5.4.2 allow remote attackers to execute arbitrary code via (1) a
crafted Content-Length HTTP header or (2) a large HTTP request,
related to an integer overflow that triggers a heap-based buffer
overflow. NOTE: this issue reportedly exists because of an incomplete
fix for CVE-2009-0840.
|
| CVE-2009-1844 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x
before 5.18 and 6.x before 6.12 allow (1) remote authenticated users
to inject arbitrary web script or HTML via crafted UTF-8 byte
sequences that are treated as UTF-7 by Internet Explorer 6 and 7,
which are not properly handled in the "HTML exports of books" feature;
and (2) allow remote authenticated users with administer taxonomy
permissions to inject arbitrary web script or HTML via the help text
of an arbitrary vocabulary. NOTE: vector 1 exists because of an
incomplete fix for CVE-2009-1575.
|
| CVE-2009-1381 |
The map_yp_alias function in functions/imap_general.php in
SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other
operating systems and versions, allows remote attackers to execute
arbitrary commands via shell metacharacters in a username string that
is used by the ypmatch program. NOTE: this issue exists because of an
incomplete fix for CVE-2009-1579.
|
| CVE-2009-1376 |
Multiple integer overflows in the msn_slplink_process_msg functions in
the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and
(2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim)
before 2.5.6 on 32-bit platforms allow remote attackers to execute
arbitrary code via a malformed SLP message with a crafted offset
value, leading to buffer overflows. NOTE: this issue exists because
of an incomplete fix for CVE-2008-2927.
|
| CVE-2009-0792 |
Multiple integer overflows in icc.c in the International Color
Consortium (ICC) Format library (aka icclib), as used in Ghostscript
8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and
earlier, allow context-dependent attackers to cause a denial of
service (heap-based buffer overflow and application crash) or possibly
execute arbitrary code by using a device file for a translation
request that operates on a crafted image file and targets a certain
"native color space," related to an ICC profile in a (1) PostScript or
(2) PDF file with embedded images. NOTE: this issue exists because of
an incomplete fix for CVE-2009-0583.
|
| CVE-2009-0419 |
Microsoft XML Core Services, as used in Microsoft Expression Web,
Office, Internet Explorer 6 and 7, and other products, does not
properly restrict access from web pages to Set-Cookie2 HTTP response
headers, which allows remote attackers to obtain sensitive information
from cookies via XMLHttpRequest calls, related to the HTTPOnly
protection mechanism. NOTE: this issue reportedly exists because of an
incomplete fix for CVE-2008-4033.
|
| CVE-2009-0356 |
Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the
(1) about:plugins and (2) about:config URIs from .desktop files, which
allows user-assisted remote attackers to bypass the Same Origin Policy
and execute arbitrary code with chrome privileges via vectors
involving the URL field in a Desktop Entry section of a .desktop file,
related to representation of about: URIs as jar:file:// URIs. NOTE:
this issue exists because of an incomplete fix for CVE-2008-4582.
|
| CVE-2009-0148 |
Multiple buffer overflows in Cscope before 15.7a allow remote
attackers to execute arbitrary code via long strings in input such as
(1) source-code tokens and (2) pathnames, related to integer overflows
in some cases. NOTE: this issue exists because of an incomplete fix
for CVE-2004-2541.
|
| CVE-2008-7256 |
mm/shmem.c in the Linux kernel before 2.6.28-rc8, when strict
overcommit is enabled and CONFIG_SECURITY is disabled, does not
properly handle the export of shmemfs objects by knfsd, which allows
attackers to cause a denial of service (NULL pointer dereference and
knfsd crash) or possibly have unspecified other impact via unknown
vectors. NOTE: this vulnerability exists because of an incomplete fix
for CVE-2010-1643.
|
| CVE-2008-7250 |
Cross-site scripting (XSS) vulnerability in Squid Analysis Report
Generator (Sarg) 2.2.4 allows remote attackers to inject arbitrary web
script or HTML via a JavaScript onload event in the User-Agent header,
which is not properly handled when displaying the Squid proxy log.
NOTE: this issue exists because of an incomplete fix for
CVE-2008-1168.
|
| CVE-2008-5716 |
xend in Xen 3.3.0 does not properly restrict a guest VM's write access
within the /local/domain xenstore directory tree, which allows guest
OS users to cause a denial of service and possibly have unspecified
other impact by writing to (1) console/tty, (2) console/limit, or (3)
image/device-model-pid. NOTE: this issue exists because of erroneous
set_permissions calls in the fix for CVE-2008-4405.
|
| CVE-2008-5236 |
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other
1.1.15 and earlier versions, allow remote attackers to execute
arbitrary code via vectors related to (1) a crafted EBML element
length processed by the parse_block_group function in
demux_matroska.c; (2) a certain combination of sps, w, and h values
processed by the real_parse_audio_specific_data and
demux_real_send_chunk functions in demux_real.c; and (3) an
unspecified combination of three values processed by the open_ra_file
function in demux_realaudio.c. NOTE: vector 2 reportedly exists
because of an incomplete fix in 1.1.15.
|
| CVE-2008-5080 |
awstats.pl in AWStats 6.8 and earlier does not properly remove quote
characters, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via the query_string parameter. NOTE: this
issue exists because of an incomplete fix for CVE-2008-3714.
|
| CVE-2008-5031 |
Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6,
allow context-dependent attackers to have an unknown impact via a
large integer value in the tabsize argument to the expandtabs method,
as implemented by (1) the string_expandtabs function in
Objects/stringobject.c and (2) the unicode_expandtabs function in
Objects/unicodeobject.c. NOTE: this vulnerability reportedly exists
because of an incomplete fix for CVE-2008-2315.
|
| CVE-2008-4310 |
httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat
Enterprise Linux 4 and 5, allows remote attackers to cause a denial of
service (CPU consumption) via a crafted HTTP request. NOTE: this
issue exists because of an incomplete fix for CVE-2008-3656.
|
| CVE-2008-4126 |
PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use
random source ports for DNS requests and does not use random
transaction IDs for DNS retries, which makes it easier for remote
attackers to spoof DNS responses, a different vulnerability than
CVE-2008-1447. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2008-4099.
|
| CVE-2008-4098 |
MySQL before 5.0.67 allows local users to bypass certain privilege
checks by calling CREATE TABLE on a MyISAM table with modified (1)
DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally
associated with pathnames without symlinks, and that can point to
tables created at a future time at which a pathname is modified to
contain a symlink to a subdirectory of the MySQL home data directory.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2008-4097.
|
| CVE-2008-4097 |
MySQL 5.0.51a allows local users to bypass certain privilege checks by
calling CREATE TABLE on a MyISAM table with modified (1) DATA
DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with
symlinks within pathnames for subdirectories of the MySQL home data
directory, which are followed when tables are created in the future.
NOTE: this vulnerability exists because of an incomplete fix for
CVE-2008-2079.
|
| CVE-2008-4018 |
swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local
users in the system group to create or overwrite an arbitrary file,
and establish weak permissions and root ownership for this file, via
unspecified vectors. NOTE: this can be leveraged to gain privileges.
NOTE: this issue exists because of an incomplete fix for
CVE-2007-5805.
|
| CVE-2008-3969 |
Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow
remote attackers to "overwrite" and "hijack" existing accounts via
unknown vectors related to "inconsistent handling of the
USTATUS_IDENTIFIED state." NOTE: this issue exists because of an
incomplete fix for CVE-2008-3920.
|
| CVE-2008-3958 |
IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a
denial of service (instance crash) via a crafted CONNECT/ATTACH data
stream that simulates a V7 client connect/attach request. NOTE: this
may overlap CVE-2008-3858. NOTE: this issue exists because of an
incomplete fix for CVE-2008-3959.
|
| CVE-2008-3860 |
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG
editors, (2) during local group creation, (3) during HTML redirects,
(4) in the HTML import, (5) in the Rich text editor, and (6) in
link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before
Hotfix 15 allow remote attackers to inject arbitrary web script or
HTML via unknown vectors, including (7) the Imported Page. NOTE: the
vulnerability in the WYSIWYG editors may exist because of an
incomplete fix for CVE-2008-2163.
|
| CVE-2008-3851 |
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on
Windows allow remote attackers to include and execute arbitrary local
files via a ..\ (dot dot backslash) in the (1) blogpost, (2) cat, and
(3) file parameters to data/inc/themes/predefined_variables.php, as
reachable through index.php; and the (4) blogpost and (5) cat
parameters to data/inc/blog_include_react.php, as reachable through
index.php. NOTE: the issue involving vectors 1 through 3 reportedly
exists because of an incomplete fix for CVE-2008-3194.
|
| CVE-2008-3703 |
The management console in the Volume Manager Scheduler Service (aka
VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows
(SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication,
which allows remote attackers to execute arbitrary code via requests
to the service socket that create "snapshots schedules" registry
values specifying future command execution. NOTE: this issue exists
because of an incomplete fix for CVE-2007-2279.
|
| CVE-2008-3215 |
libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to
cause a denial of service via a malformed Petite file that triggers an
out-of-bounds memory access. NOTE: this issue exists because of an
incomplete fix for CVE-2008-2713.
|
| CVE-2008-3076 |
The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted
attackers to execute arbitrary code via shell metacharacters in
filenames used by the execute and system functions within the (1) mz
and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test
cases. NOTE: this issue reportedly exists because of an incomplete
fix for CVE-2008-2712.
|
| CVE-2008-3075 |
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10,
allows user-assisted attackers to execute arbitrary code via the "!"
(exclamation point) shell metacharacter in (1) the filename of a ZIP
archive and possibly (2) the filename of the first file in a ZIP
archive, which is not properly handled by zip.vim in the VIM ZIP
plugin (zipPlugin.vim) v.11 through v.21, as demonstrated by the
zipplugin and zipplugin.v2 test cases. NOTE: this issue reportedly
exists because of an incomplete fix for CVE-2008-2712. NOTE: this
issue has the same root cause as CVE-2008-3074. NOTE: due to the
complexity of the associated disclosures and the incomplete
information related to them, there may be inaccuracies in this CVE
description and in external mappings to this identifier.
|
| CVE-2008-3074 |
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10,
allows user-assisted attackers to execute arbitrary code via the "!"
(exclamation point) shell metacharacter in (1) the filename of a tar
archive and possibly (2) the filename of the first file in a tar
archive, which is not properly handled by the VIM TAR plugin (tar.vim)
v.10 through v.22, as demonstrated by the shellescape, tarplugin.v2,
tarplugin, and tarplugin.updated test cases. NOTE: this issue
reportedly exists because of an incomplete fix for CVE-2008-2712.
NOTE: this issue has the same root cause as CVE-2008-3075. NOTE: due
to the complexity of the associated disclosures and the incomplete
information related to them, there may be inaccuracies in this CVE
description and in external mappings to this identifier.
|
| CVE-2008-2376 |
Integer overflow in the rb_ary_fill function in array.c in Ruby before
revision 17756 allows context-dependent attackers to cause a denial of
service (crash) or possibly have unspecified other impact via a call
to the Array#fill method with a start (aka beg) argument greater than
ARY_MAX_SIZE. NOTE: this issue exists because of an incomplete fix for
other closely related integer overflows.
|
| CVE-2008-1930 |
The cookie authentication method in WordPress 2.5 relies on a hash of
a concatenated string containing USERNAME and EXPIRY_TIME, which
allows remote attackers to forge cookies by registering a username
that results in the same concatenated string, as demonstrated by
registering usernames beginning with "admin" to obtain administrator
privileges, aka a "cryptographic splicing" issue. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2007-6013.
|
| CVE-2008-1897 |
The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x,
1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition
A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW
before 1.0.3; Appliance Developer Kit 0.x.x; and s800i before 1.1.0.3,
when configured to allow unauthenticated calls, does not verify that
an ACK response contains a call number matching the server's reply to
a NEW message, which allows remote attackers to cause a denial of
service (traffic amplification) via a spoofed ACK response that does
not complete a 3-way handshake. NOTE: this issue exists because of an
incomplete fix for CVE-2008-1923.
|
| CVE-2008-1311 |
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and
earlier allows remote attackers to cause a denial of service (daemon
hang) by uploading a file named (1) '|' (pipe), (2) '"' (quotation
mark), or (3) "<>" (less than, greater than); or (4) a file with a
long name. NOTE: the issue for vector 4 might exist because of an
incomplete fix for CVE-2008-1312.
|
| CVE-2008-1117 |
Directory traversal vulnerability in the Notes (aka Flash Notes or
instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for
Windows, and possibly 8.7 for Mac OS X, allows remote attackers to
upload files to arbitrary locations via a destination filename with a
\ (backslash) character followed by ../ (dot dot slash) sequences.
NOTE: this can be leveraged for code execution by writing to a Startup
folder. NOTE: this issue reportedly exists because of an incomplete
fix for CVE-2007-4220.
|
| CVE-2008-0760 |
Directory traversal vulnerability in SafeNet Sentinel Protection
Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and
earlier, allows remote attackers to read arbitrary files via a ..\
(dot dot backslash) in the URI. NOTE: this issue reportedly exists
because of an incomplete fix for CVE-2007-6483.
|
| CVE-2008-0639 |
Stack-based buffer overflow in the EnumPrinters function in the
Spooler service (nwspool.dll) in Novell Client 4.91 SP2, SP3, and SP4
for Windows allows remote attackers to execute arbitrary code via a
crafted RPC request, aka Novell bug 353138, a different vulnerability
than CVE-2006-5854. NOTE: this issue exists because of an incomplete
fix for CVE-2007-6701.
|
| CVE-2007-6601 |
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11,
8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when
local trust or ident authentication is used, allows remote attackers
to gain privileges via unspecified vectors. NOTE: this issue exists
because of an incomplete fix for CVE-2007-3278.
|
| CVE-2007-6010 |
Unspecified vulnerability in pioneers (formerly gnocatan) 0.11.3
allows remote attackers to cause a denial of service (daemon crash)
via unspecified vectors that trigger an assert error. NOTE: this issue
reportedly exists because of an incomplete fix for CVE-2007-5933.
|
| CVE-2007-5333 |
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0
through 4.1.36 does not properly handle (1) double quote (")
characters or (2) %5C (encoded backslash) sequences in a cookie value,
which might cause sensitive information such as session IDs to be
leaked to remote attackers and enable session hijacking attacks. NOTE:
this issue exists because of an incomplete fix for CVE-2007-3385.
|
| CVE-2007-5124 |
The embedded Internet Explorer server control in AOL Instant Messenger
(AIM) 6.5.3.12 and earlier allows remote attackers to execute
arbitrary code via unspecified web script or HTML in an instant
message, related to AIM's filtering of "specific tags and attributes"
and the lack of Local Machine Zone lockdown. NOTE: this issue
reportedly exists because of an incomplete fix for CVE-2007-4901.
|
| CVE-2007-3544 |
Unrestricted file upload vulnerability in (1) wp-app.php and (2)
app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote
authenticated users to upload and execute arbitrary PHP code via
unspecified vectors, possibly related to the wp_postmeta table and the
use of custom fields in normal (non-attachment) posts. NOTE: this
issue reportedly exists because of an incomplete fix for
CVE-2007-3543.
|
| CVE-2007-3204 |
SQL injection vulnerability in auth.php in Just For Fun Network
Management System (JFFNMS) 0.8.4-pre2 allows remote attackers to
execute arbitrary SQL commands via the pass parameter. NOTE: this
issue reportedly exists because of an initial incomplete fix for
CVE-2007-3190. The provenance of this information is unknown; the
details are obtained solely from third party information.
|