The Axis Video Server does not properly secure sensitive information, allowing an attacker to gather details about server operation and traffic that could lead to further attacks.
A format string vulnerability has been discovered in AMX Mod 0.9.2 and earlier which may be exploitable to execute arbitrary code on a target Half-Life server. The problem occurs when calling the 'amx_say' command. By passing specially constructed format specifiers as an argument to the command, it is possible to modify arbitrary locations in memory.
A buffer overflow vulnerability has been reported for moxftp. The vulnerability occurs when moxftp is parsing 'Welcome' banner messages from remote FTP servers. When moxftp receives an overly long FTP banner, it will trigger the overflow condition. An attacker can exploit this vulnerability by enticing a victim moxftp user to connect to a malicious FTP server. Any attacker-supplied code will be executed on the victim system with the privileges of the moxftp process.
php-board is vulnerable to an information disclosure vulnerability due to insufficient access control. An attacker can access user files and gain access to php-board user and administrative passwords by requesting the user files via the web.
A buffer overflow vulnerability has been reported in the stmkfont utility shipped with HP-UX systems. The problem occurs due to insufficient bounds checking on user-suplied data to the alternate typeface library command-line option. A local attacker may be able to exploit this issue to execute arbitrary code with elevated privileges. All Avaya PDS 9 and 11 platforms are vulnerable to this issue. Avaya PDS 12 platforms running on HP-UX 11.00 are vulnerable as well. PDS 12 versions running on HP-UX 11.11 are not vulnerable.
A buffer overrun vulnerability exists in the Microsoft Windows XP Redirector due to improper handling of certain parameters passed to it. If one of these parameters is unusually long, a buffer can be overrun, resulting in either Windows XP crashing or code execution with elevated privileges.
A vulnerability has been reported for Opera 7 browsers for Microsoft Windows operating systems. The vulnerability exists in the Opera JavaScript console. Attackers may exploit the vulnerability to execute script code in a sensitive context. Exploitation of this vulnerability may lead to disclosure of local file contents.
This exploit was coded by Cody Tubbs (loophole of hhp) and tested on SuSE 6.4/2.2.14. It is a local buffer overflow exploit which takes advantage of a bug found by skeptik. It uses a static char shellcode and a long get_sp() to overwrite the return address. The exploit was tested on a non-s*id system by default, p.o.e. only.
A buffer overflow condition has been reported for the CuteFTP application. The vulnerability is due to insufficient bounds checking performed on certain FTP command responses. If CuteFTP is used to connect to a malicious FTP server that sends an overly long response to the LIST command, the buffer overflow condition will be triggered. Code execution may be possible.
PHP TopSites is vulnerable to SQL injection due to insufficient sanitization of user-supplied URI parameters. An attacker can embed malicious SQL commands into certain page requests, which can result in the disclosure of another user's private information.