CVE-2004-2402
Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board...
Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board...
Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text." Date published : 2005-08-17 http://www.securityfocus.com/bid/10106 http://support.ipswitch.com/kb/IM-20031219-DF01.htm
WinFTP Server 1.6 stores username and password credentials in plaintext in the datauser.wfd file, which allows local users to gain access to the credentials. Date published : 2005-08-17 http://www.securityfocus.com/bid/11749 http://www.osvdb.org/12122
Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (CPU consumption) via delayed responses to DNS queries. Date published : 2005-08-17 http://www.securecomputing.com/pdf/SW61002Rel_Notes_0512.pdf http://www.osvdb.org/6231
Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql,...
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows...
passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM. Date published : 2005-08-17 http://www.securityfocus.com/bid/10370 http://www.mandriva.com/security/advisories?name=MDKSA-2004:045
Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer. Date published : 2005-08-17 http://www.securityfocus.com/bid/10370 http://www.mandriva.com/security/advisories?name=MDKSA-2004:045
Off-by-one error in passwd 0.68 and earlier, when using the –stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction...
Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS. Date published : 2005-08-17...
libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, related to read failures and other bugs. Date published : 2005-08-17 http://www.securityfocus.com/bid/10368 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120168
Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service a message with an empty tag. Date published : 2005-08-17 http://www.securityfocus.com/bid/9710 http://www.jabberstudio.org/projects/jabber-gg-transport/releases/view.php?id=429
The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors. Date published : 2005-08-17...
Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration. Date published : 2005-08-17 http://www.securityfocus.com/bid/9710 http://www.jabberstudio.org/projects/jabber-gg-transport/releases/view.php?id=429