Weekly Vulnerabilities Reports > October 25 to 31, 2004

Overview

9 new vulnerabilities reported during this period, including 1 critical vulnerabilities and 2 high severity vulnerabilities. This weekly summary report vulnerabilities in 9 products from 6 vendors including Mozilla, Openwfe, SUN, Hawking Technology, and Moniwiki. Vulnerabilities are notably categorized as .

  • 9 reported vulnerabilities are remotely exploitables.
  • 9 reported vulnerabilities are exploitable by an anonymous user.
  • Mozilla has the most reported vulnerabilities, with 3 reported vulnerabilities.
  • NET Integration Technologies INC has the most reported critical vulnerabilities, with 1 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

1 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2004-10-26 CVE-2004-1636 NET Integration Technologies INC Remote Buffer Overflow vulnerability in NET Integration Technologies Inc. Wvtftp 0.9

Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.

10.0

2 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2004-10-30 CVE-2004-1350 SUN Buffer Overflow vulnerability in SUN Java System web Proxy Server 3.6

Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests.

7.5
2004-10-26 CVE-2004-1637 Hawking Technology Unspecified vulnerability in Hawking Technology Har11A DSL Router

The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections.

7.5

6 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2004-10-26 CVE-2004-1639 Mozilla Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.
5.0
2004-10-25 CVE-2004-1634 Mozilla Authentication Bypass and Information Disclosure vulnerability in Mozilla Bugzilla

show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.

5.0
2004-10-25 CVE-2004-1633 Mozilla Remote Security vulnerability in Bugzilla

process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.

5.0
2004-10-25 CVE-2004-1631 Openwfe Remote Cross-Site Scripting And Connection Proxy vulnerability in OpenWFE

Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the results.

5.0
2004-10-25 CVE-2004-1632 Moniwiki Cross-Site Scripting vulnerability in Moniwiki 1.0.8

Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php.

4.3
2004-10-25 CVE-2004-1630 Openwfe Remote Cross-Site Scripting And Connection Proxy vulnerability in OpenWFE

Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url parameter.

4.3

0 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS