Search: "isc"

277 CVEs found

Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaSc...

Published: 2006-03-07
Products: 1
Vendors:
microsoft

Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the acti...

Published: 2006-03-30
Products: 1
Vendors:
apache
CVE-2006-2073
5.0 MEDIUM

Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.

Published: 2006-04-27
Products: 13
Vendors:
isc

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a ma...

Published: 2006-05-20
Products: 5
Vendors:
microsoft
CVE-2006-3122
5.0 MEDIUM

The supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) via a DHCPDISCOVER packet with a 32 byte client-iden...

Published: 2006-08-09
Products: 1
Vendors:
isc

Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (...

Published: 2007-01-25
Products: 6
Vendors:
isc
CVE-2007-0494
4.3 MEDIUM

ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service ...

Published: 2007-01-25
Products: 92
Vendors:
isc
CVE-2007-0602
6.9 MEDIUM

Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan, allows local users to gain privileges via a long command line argument, a diff...

Published: 2007-01-30
Products: 1
Vendors:
trend_micro

Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of que...

Published: 2007-05-02
Products: 2
Vendors:
isc

Buffer overflow in the isChecked function in toolbar.dll in Netsprint Toolbar 1.1 might allow remote attackers to execute arbitrary code via unspecified vectors.

Published: 2007-05-15
Products: 1
Vendors:
netsprint

usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to a...

Published: 2007-06-14
Products: 2
Vendors:
redhat

usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 uses a semaphore with insecure permissions (world-writable/world-readable) for managing log messages using shared memory, which...

Published: 2007-06-14
Products: 3
Vendors:
redhat
CVE-2007-2925
5.8 MEDIUM

The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive ...

Published: 2007-07-24
Products: 3
Vendors:
isc
CVE-2007-2926
4.3 MEDIUM

ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it eas...

Published: 2007-07-24
Products: 7
Vendors:
isc
CVE-2007-4249
4.3 MEDIUM

The isChecked function in Toolbar.DLL in the ExportNation toolbar for Internet Explorer allows remote attackers to cause a denial of service (NULL dereference and browser crash) via unspecified vector...

Published: 2007-08-08
Products: 1
Vendors:
exportnation
CVE-2007-4250
5.0 MEDIUM

The isChecked function in Toolbar.DLL in Advanced Searchbar before 3.33 allows remote attackers to cause a denial of service (NULL dereference and browser crash) via unspecified vectors.

Published: 2007-08-08
Products: 1
Vendors:
advanced_searchbar
CVE-2007-2930
4.3 MEDIUM

The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answ...

Published: 2007-09-12
Products: 1
Vendors:
isc
CVE-2007-0062
10.0 HIGH

Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0....

Published: 2007-09-21
Products: 19
Vendors:
vmware

Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service at...

Published: 2007-10-06
Products: 17
Vendors:
borland_software
CVE-2007-5246
10.0 HIGH

Multiple stack-based buffer overflows in Firebird LI 2.0.0.12748 and 2.0.1.12855, and WI 2.0.0.12748 and 2.0.1.12855, allow remote attackers to execute arbitrary code via (1) a long attach request on ...

Published: 2007-10-06
Products: 4
Vendors:
firebirdsql