Opera 12.15 is vulnerable to a Denial of Service attack due to a VTable Corruption vulnerability. The vulnerability occurs when a frame and meter element are created and appended to the document body. When the getBoundingClientRect() method is called on the frame element, the VTable of the meter element is corrupted, causing the code to crash.
This module exploits a vulnerability on EPATHOBJ::pprFlattenRec due to the usage of uninitialized data which allows to corrupt memory. At the moment, the module has been tested successfully on Windows XP SP3, Windows 2003 SP1, and Windows 7 SP1.
GLPI is prone to a remote PHP code-execution vulnerability. An attacker can exploit this issue to inject and execute arbitrary PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible. An attacker can exploit this issue using a web browser.
This module abuses the insecure invoke() method of the ProviderSkeleton class that allows to call arbitrary static methods with user supplied arguments. The vulnerability affects Java version 7u21 and earlier.
Because many functions are not protected by CSRF-Tokens, it's possible (under certain conditions) to modify System-Settings, Firewall-Policies or take control over the hole firewall. An Attacker needs to know the IP of the device. An Administrator needs an authenticated connection to the device.
Barracuda SSL VPN suffers from multiple stored XSS vulnerabilities when parsing user input to several parameters via POST method. Attackers can exploit these weaknesses to execute arbitrary HTML and script code in a user's browser session.
Adrenalin Player 2.2.5.3 is vulnerable to a SEH-Buffer Overflow vulnerability. An attacker can exploit this vulnerability by crafting a malicious .wvx file containing a specially crafted payload. When the file is opened, the payload is executed, allowing the attacker to execute arbitrary code on the target system.
This module exploits a buffer overflow in Audio Code 0.8.18. The vulnerability occurs when adding an .lst, allowing arbitrary code execution with the privileges of the user running AudioCoder. This module has been tested successfully on AudioCoder 0.8.22 over Windows XP SP3 and Windows 7 SP1.
C.P.Sub <= v4.5 use 'user_com=' parameter to identify if the user has admin privilege. Therefore an attacker could simply change the value for 'user_com=' parameter to gain admin privilege. There are some default accounts for C.P.Sub <= v4.5 that allows an attacker to access back-end management page. It could lead to further attack.
AVS Media Player version 4.1.11.100 is vulnerable to a denial of service attack when a specially crafted .ac3 file is opened. The file contains a buffer of bytes followed by a large amount of junk data and a small amount of bob data. When the file is opened, the application crashes.