An unauthenticated remote attacker can submit various malformed service requests via Bluetooth, triggering a buffer overflow and executing arbitrary code on vulnerable devices using WIDCOMM Bluetooth Connectivity Software. All releases prior to 3.0 are affected.
5ec2b26e117a8391be03708d270e39f990dae23341935158de2640217287f268
IBM DB2 version 7.2 for Windows is vulnerable to a stack overflow in the INVOKE command that allows any attacker with Connect privileges to execute arbitrary code as the Administrators group.
dff1915f53bfe2f9a06216f85950a93b855ea98e3435b70fda2d599fd7b98496
Westpoint Security Advisory wp-02-0012 - The Carello shopping cart v1.3 uses hidden fields to specify names of executables on the server, allowing an attacker to run arbitrary commands.
9887d380b7d1e54dae208b58a265e0fcad7f19f519c4c30e79789a422c384c4c
Westpoint Security Advisory wp-02-0008 - Apache Tomcat v4.0.3 is vulnerable to cross site scripting attacks by using the /servlet/ mapping. Linux and Win32 versions of Tomcat are vulnerable.
7c8753a353b10b9fcac8e6d4fcd9c7fd8be17eae6139f7796cc2b8b8fa6dea83
Westpoint Security Advisory wp-02-0001 - The GoAhead Web Server v2.1 for Windows NT/98/95/CE, Embedded Linux, Netware, and others contains directory traversal and cross site scripting vulnerabilities. Exploit URL's included.
3e2b101f0ae13c006aead327c7e7c21f64f42fc6791980b2cd6bb6c96186df8d
Westpoint Security Advisory - SQLXML allows XML data to be transferred to and from SQL Server, returning database queries as XML. SQLXML has two vulnerabilities - a buffer overflow in the SQLXML ISAPI filter and a cross site scripting vulnerability. These bugs are discussed in MS02-030.
11b451a50a7794ab52be537a852add9ac09a0ab37b6dff3b1edbf49c061125b0
NewAtlanta ServletExec ISAPI v4.1 contains three vulnerabilities. Remote users can read any file in the webroot, crash the server, and display the physical path of the web root. Patch available here.
fc28cc03d24fa98eb266f32deaf3daa32abc63bfc958831609ba5849b34c2d4a