Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2011-03-18 CVE-2008-7277 Permissions, Privileges, and Access Controls vulnerability in Otrs
Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.
network
low complexity
otrs CWE-264
6.5
2011-03-18 CVE-2008-7276 Permissions, Privileges, and Access Controls vulnerability in Otrs
Kernel/System/Web/Request.pm in Open Ticket Request System (OTRS) before 2.3.2 creates a directory under /tmp/ with 1274 permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations, related to incorrect interpretation of 0700 as a decimal value.
local
low complexity
otrs CWE-264
4.6
2011-03-18 CVE-2008-7275 Cross-Site Scripting vulnerability in Otrs
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTicketMailbox or (2) CustomerTicketOverView.
network
otrs CWE-79
4.3
2011-03-18 CVE-2011-1148 Resource Management Errors vulnerability in PHP
Use-after-free vulnerability in the substr_replace function in PHP 5.3.6 and earlier allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by using the same variable for multiple arguments.
network
low complexity
php CWE-399
7.5
2011-03-16 CVE-2011-1432 Unspecified vulnerability in SCO Scoofficeserver
The STARTTLS implementation in SCO SCOoffice Server does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
network
sco
6.8
2011-03-16 CVE-2011-1431 Unspecified vulnerability in Frederik Vermeulen Netqmail 1.06
The STARTTLS implementation in qmail-smtpd.c in qmail-smtpd in the netqmail-1.06-tls patch for netqmail 1.06 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
6.8
2011-03-16 CVE-2011-1430 Improper Input Validation vulnerability in Ipswitch Imail
The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
network
ipswitch CWE-20
6.8
2011-03-16 CVE-2011-1429 Improper Input Validation vulnerability in Mutt
Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.
network
mutt CWE-20
5.8
2011-03-16 CVE-2011-1153 USE of Externally-Controlled Format String vulnerability in PHP
Multiple format string vulnerabilities in phar_object.c in the phar extension in PHP 5.3.5 and earlier allow context-dependent attackers to obtain sensitive information from process memory, cause a denial of service (memory corruption), or possibly execute arbitrary code via format string specifiers in an argument to a class method, leading to an incorrect zend_throw_exception_ex call.
network
low complexity
php CWE-134
7.5
2011-03-16 CVE-2011-1094 Improper Input Validation vulnerability in Redhat Kdelibs
kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a certificate issued by a legitimate Certification Authority for an IP address, a different vulnerability than CVE-2009-2702.
network
redhat CWE-20
4.3