nux_kernel:2.4.1cpe:/o:linux:linux_kernel:2.4.15cpe:/o:microsoft:windows_2000:::servercpe:/o:linux:linux_kernel:2.4.17cpe:/o:linux:linux_kernel:2.4.14cpe:/o:linux:linux_kernel:2.4.2cpe:/o:microsoft:windows_2000:::professionalcpe:/o:linux:linux_kernel:2.4.11cpe:/o:linux:linux_kernel:2.4.5cpe:/o:linux:linux_kernel:2.4.16cpe:/o:microsoft:windows_2000::sp1:professionalcpe:/o:linux:linux_kernel:2.4.13cpe:/o:linux:linux_kernel:2.4.3CVE-2003-00012003-01-17T00:00:00.000-05:002015-11-24T13:05:47.073-05:005.0NETWORKLOWNONEPARTIALNONENONEhttp://nvd.nist.gov2015-11-24T12:23:33.593-05:00CERT-VNVU#412115BUGTRAQ20150402 NEW : VMSA-2015-0003 VMware product updates address critical information disclosure issue in JREBUGTRAQ20030117 Re: More information regarding EtherleakBUGTRAQ20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)REDHATRHSA-2003:088REDHATRHSA-2003:025OSVDB9962CONFIRMhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlMISChttp://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdfATSTAKEA010603-1FULLDISC20150402 NEW : VMSA-2015-0003 VMware product updates address critical information disclosure issue in JREMISChttp://packetstormsecurity.com/files/131271/VMware-Security-Advisory-2015-0003.htmlBUGTRAQ20030110 More information regarding EtherleakVULNWATCH20030110 More information regarding EtherleakMultiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.cpe:/a:tcp:tcpCVE-2004-02302004-08-18T00:00:00.000-04:002015-11-24T13:06:40.597-05:005.0NETWORKLOWNONENONENONEPARTIALhttp://nvd.nist.gov2015-11-24T12:17:30.930-05:00CERTTA04-111ACERT-VNVU#415294CONFIRMhttps://kc.mcafee.com/corporate/index?page=content&id=SB10053XFtcp-rst-dos(15886)VUPENADV-2006-3983MISChttp://www.uniras.gov.uk/vuls/2004/236929/index.htmBID10183BUGTRAQ20150402 NEW : VMSA-2015-0003 VMware product updates address critical information disclosure issue in JREHPSSRT061264OSVDB4030CONFIRMhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlMSMS06-064MSMS05-019CISCO20040420 TCP Vulnerabilities in Multiple IOS-Based Cisco ProductsFULLDISC20150402 NEW : VMSA-2015-0003 VMware product updates address critical information disclosure issue in JREMISChttp://packetstormsecurity.com/files/131271/VMware-Security-Advisory-2015-0003.htmlHPSSRT4696BUGTRAQ20040425 Perl code exploting TCP not checking RST ACK.CONFIRMhttp://kb.juniper.net/JSA10638SGI20040403-01-ASCOSCOSA-2005.14SCOSCOSA-2005.9SCOSCOSA-2005.3NETBSDNetBSD-SA2004-006TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.cpe:/a:vastal:phpvid:1.1cpe:/a:vastal:phpvid:1.2CVE-2008-23352008-05-19T09:20:00.000-04:002015-11-24T11:45:25.057-05:004.3NETWORKMEDIUMNONENONEPARTIALNONEhttp://nvd.nist.gov2015-11-24T10:50:05.737-05:00XFphpvid-query-xss(42450)VUPENADV-2008-2552BID29238MILW0RM6422EXPLOIT-DB27519MISChttp://tetraph.com/security/xss-vulnerability/vastal-i-tech-phpvid-1-2-3-multiple-xss-cross-site-scripting-security-vulnerabilities/FULLDISC20150310 Vastal I-tech phpVID 1.2.3 Multiple XSS (Cross-site Scripting) Security VulnerabilitiesMISChttp://packetstormsecurity.com/files/130755/Vastal-I-tech-phpVID-1.2.3-Cross-Site-Scripting.htmlMISChttp://packetstormsecurity.com/files/122746/PHP-VID-XSS-SQL-Injection-CRLF-Injection.htmlOSVDB45171MISChttp://holisticinfosec.org/content/view/65/45/Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 1.2.3 is also affected.cpe:/a:redhat:enterprise_virtualization:3.5cpe:/a:jasper_project:jasper:1.900.1CVE-2008-35222008-10-02T14:18:05.790-04:002015-11-24T11:46:04.933-05:0010.0NETWORKLOWNONECOMPLETECOMPLETECOMPLETEhttp://nvd.nist.gov2015-11-24T10:05:46.467-05:00ALLOWS_ADMIN_ACCESSXFjasper-jasstreamprintf-bo(45623)UBUNTUUSN-742-1BID31470MANDRIVAMDVSA-2009:164MANDRIVAMDVSA-2009:144MANDRIVAMDVSA-2009:142GENTOOGLSA-200812-18REDHATRHSA-2015:0698MISChttp://bugs.gentoo.org/show_bug.cgi?id=222819MISChttp://bugs.gentoo.org/attachment.cgi?id=163282&action=viewBuffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.cpe:/o:canonical:ubuntu_linux:10.04::~~lts~~~cpe:/o:canonical:ubuntu_linux:8.04:-:ltscpe:/o:canonical:ubuntu_linux:10.10cpe:/a:sun:openoffice.org:2.1.0cpe:/a:sun:openoffice.org:2.3.0cpe:/a:sun:openoffice.org:2.2.1CVE-2009-33012010-02-16T14:30:00.533-05:002015-11-17T10:59:44.723-05:009.3NETWORKMEDIUMNONECOMPLETECOMPLETECOMPLETEhttp://nvd.nist.gov2015-11-17T10:02:50.097-05:00CERTTA10-287ACONFIRMhttps://bugzilla.redhat.com/show_bug.cgi?id=533038XFopenoffice-word-sprmtdeftable-bo(56240)VUPENADV-2010-2905VUPENADV-2010-0635VUPENADV-2010-0366UBUNTUUSN-903-1BID38218REDHATRHSA-2010:0101CONFIRMhttp://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlCONFIRMhttp://www.openoffice.org/security/cves/CVE-2009-3301-3302.htmlCONFIRMhttp://www.openoffice.org/security/bulletin.htmlMANDRIVAMDVSA-2010:221GENTOOGLSA-201408-19DEBIANDSA-1995SECTRACK1023591SUSESUSE-SA:2010:017Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.CVE-2015-83302015-11-24T15:59:25.897-05:002015-11-24T15:59:26.930-05:00MISChttps://www.onapsis.com/blog/analyzing-sap-security-notes-november-2015MISChttp://erpscan.com/advisories/erpscan-15-032-sap-pco-agent-dos-vulnerability/The PCo agent in SAP Plant Connectivity (PCo) allows remote attackers to cause a denial of service (memory corruption and agent crash) via crafted xMII requests, aka SAP Security Note 2238619.