Search: "isc"

277 CVEs found

Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute ...

Published: 2007-10-11
Products: 222
Vendors:
ubuntu redhat sun debian openbsd

libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of ser...

Published: 2007-10-16
Products: 1
Vendors:
suse

iSCSI Enterprise Target (iscsitarget) 0.4.15 uses weak permissions for /etc/ietd.conf, which allows local users to obtain passwords.

Published: 2007-11-05
Products: 14
Vendors:
debian iscsitarget
CVE-2008-0122
10.0 HIGH

Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of s...

Published: 2008-01-16
Products: 43
Vendors:
freebsd isc
CVE-2008-0911
6.5 MEDIUM

SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.

Published: 2008-02-22
Products: 1
Vendors:
iscripts
CVE-2008-1772
5.0 MEDIUM

iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information.

Published: 2008-04-14
Products: 1
Vendors:
iscripts
CVE-2008-1790
6.5 MEDIUM

Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo file in the "Manage Settings" functionality. NOTE...

Published: 2008-04-15
Products: 1
Vendors:
iscripts

SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.

Published: 2008-04-16
Products: 1
Vendors:
iscripts
CVE-2008-1880
5.0 MEDIUM

The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authen...

Published: 2008-05-12
Products: 3
Vendors:
gentoo firebird

SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the produid parameter.

Published: 2008-09-22
Products: 1
Vendors:
iscripts

Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to cause a denial of service (UDP client handler termination) via unknown vectors.

Published: 2008-09-22
Products: 3
Vendors:
isc
CVE-2009-0692
10.0 HIGH

Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP serv...

Published: 2009-07-14
Products: 5
Vendors:
isc
CVE-2009-1892
5.0 MEDIUM

dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via u...

Published: 2009-07-17
Products: 5
Vendors:
isc
CVE-2009-0696
4.3 MEDIUM

The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a ...

Published: 2009-07-29
Products: 65
Vendors:
isc
CVE-2008-7135
4.3 MEDIUM

toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked method, a different vector than CVE-2008-7136.

Published: 2009-09-01
Products: 1
Vendors:
icq

Multiple unspecified vulnerabilities in the (1) iscsiadm and (2) iscsitadm programs in Sun Solaris 10, and OpenSolaris snv_28 through snv_109, allow local users with certain RBAC execution profiles to...

Published: 2009-09-24
Products: 165
Vendors:
sun
CVE-2009-1297
4.4 MEDIUM

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symli...

Published: 2009-10-23
Products: 4
Vendors:
novell opensuse

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disab...

Published: 2009-11-25
Products: 169
Vendors:
isc
CVE-2010-0097
4.3 MEDIUM

ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attack...

Published: 2010-01-22
Products: 189
Vendors:
isc
CVE-2010-0290
4.0 MEDIUM

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), all...

Published: 2010-01-22
Products: 168
Vendors:
isc