|
311801
|
5.0 |
MEDIUM
|
geovision
|
digital_surveillance_system
|
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.
|
CWE-22
Path Traversal
|
CVE-2009-5087
|
2024-11-21 10:11 |
2011-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311802
|
4.3 |
MEDIUM
|
juniper
|
idp
|
Cross-site scripting (XSS) vulnerability in Appliance Configuration Manager (ACM) in Juniper IDP 4.1 before 4.1r3 and 4.2 before 4.2r1 allows remote attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2009-5086
|
2024-11-21 10:11 |
2011-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311803
|
5.0 |
MEDIUM
|
libpng
|
libpng
|
Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a J…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2009-5063
|
2024-11-21 10:11 |
2011-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311804
|
2.6 |
LOW
|
ibm
|
tivoli_federated_identity_manager
|
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-par…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5085
|
2024-11-21 10:11 |
2011-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311805
|
1.9 |
LOW
|
ibm
|
tivoli_federated_identity_manager
|
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry containing a passwor…
|
CWE-310
Cryptographic Issues
|
CVE-2009-5084
|
2024-11-21 10:11 |
2011-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311806
|
6.8 |
MEDIUM
|
ibm
|
tivoli_federated_identity_manager
|
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login rejection upon receiving an OP-Identifier from an Op…
|
CWE-287
Improper Authentication
|
CVE-2009-5083
|
2024-11-21 10:11 |
2011-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311807
|
3.3 |
LOW
|
gnu
|
groff
|
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes i…
|
CWE-59
Link Following
|
CVE-2009-5082
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311808
|
3.3 |
LOW
|
gnu
|
groff
|
The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the te…
|
CWE-59
Link Following
|
CVE-2009-5081
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311809
|
3.3 |
LOW
|
gnu
|
groff
|
The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain f…
|
CWE-59
Link Following
|
CVE-2009-5080
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311810
|
3.3 |
LOW
|
gnu
|
groff
|
The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack …
|
CWE-59
Link Following
|
CVE-2009-5079
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311811
|
6.5 |
MEDIUM
Network
|
gnu apple
|
groff mac_os_x
|
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbi…
|
CWE-254
7PK - Security Features
|
CVE-2009-5078
|
2024-11-21 10:11 |
2011-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311812
|
3.3 |
LOW
|
apple gnu
|
mac_os_x groff
|
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
|
CWE-59
Link Following
|
CVE-2009-5044
|
2024-11-21 10:11 |
2011-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311813
|
7.5 |
HIGH
|
creloaded
|
cre_loaded
|
CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) i…
|
CWE-287
Improper Authentication
|
CVE-2009-5077
|
2024-11-21 10:11 |
2011-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311814
|
7.5 |
HIGH
|
creloaded
|
cre_loaded
|
CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password…
|
CWE-287
Improper Authentication
|
CVE-2009-5076
|
2024-11-21 10:11 |
2011-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311815
|
5.0 |
MEDIUM
|
viewvc
|
viewvc
|
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a …
|
CWE-399
Resource Management Errors
|
CVE-2009-5024
|
2024-11-21 10:11 |
2011-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311816
|
5.8 |
MEDIUM
|
zeacom
|
chat_server
|
Zeacom Chat Server before 5.1 uses too short a random string for the JSESSIONID value, which makes it easier for remote attackers to hijack sessions or cause a denial of service (Chat Server crash or…
|
CWE-310
Cryptographic Issues
|
CVE-2010-0217
|
2024-11-21 10:11 |
2011-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311817
|
4.3 |
MEDIUM
|
monkeysaudio
|
monkey\'s_audio
|
Monkey's Audio before 4.02 allows remote attackers to cause a denial of service (application crash) via a malformed APE file.
|
CWE-399
Resource Management Errors
|
CVE-2009-5075
|
2024-11-21 10:11 |
2011-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311818
|
5.0 |
MEDIUM
|
inventivetec
|
mediacast
|
authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the error messages returned for requests that use the Us…
|
CWE-310
Cryptographic Issues
|
CVE-2010-0216
|
2024-11-21 10:11 |
2011-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311819
|
6.8 |
MEDIUM
|
libtiff
|
libtiff
|
Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-5022
|
2024-11-21 10:11 |
2011-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311820
|
10.0 |
HIGH
|
mojolicious
|
mojolicious
|
Unspecified vulnerability in the MojoX::Dispatcher::Static implementation in Mojolicious before 0.991250 has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-5074
|
2024-11-21 10:11 |
2011-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311821
|
4.0 |
MEDIUM
|
ibm
|
tivoli_directory_server
|
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) by adding a nested g…
|
CWE-399
Resource Management Errors
|
CVE-2009-5073
|
2024-11-21 10:11 |
2011-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311822
|
4.0 |
MEDIUM
|
ibm
|
tivoli_directory_server
|
Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 (aka 6.0.0.8-TIV-ITDS-IF0003) allows remote authenticated users to cause a denial of service (memo…
|
CWE-399
Resource Management Errors
|
CVE-2009-5072
|
2024-11-21 10:11 |
2011-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311823
|
10.0 |
HIGH
|
hp
|
palm_pre_webos
|
Unspecified vulnerability in Palm Pre WebOS before 1.2.1 has unknown impact and attack vectors related to an "included contact template file."
|
NVD-CWE-noinfo
|
CVE-2009-5071
|
2024-11-21 10:11 |
2011-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311824
|
4.3 |
MEDIUM
|
mark_pilgrim
|
feedparser
|
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via …
|
CWE-79
Cross-site Scripting
|
CVE-2009-5065
|
2024-11-21 10:11 |
2011-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311825
|
6.9 |
MEDIUM
|
gnu
|
glibc
|
ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADE…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5064
|
2024-11-21 10:11 |
2011-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311826
|
3.5 |
LOW
|
ibm
|
lotus_quickr
|
IBM Lotus Quickr 8.1 before 8.1.0.15 services for Lotus Domino on AIX allows remote authenticated users to cause a denial of service (daemon crash) by subscribing to an Atom feed, aka SPR JRIE7VKMP9.
|
CWE-399
Resource Management Errors
|
CVE-2009-5062
|
2024-11-21 10:11 |
2011-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311827
|
2.1 |
LOW
|
ibm
|
lotus_quickr
|
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.14 services for Lotus Domino, when Domino Native Authentication is enabled, might allow remote authenticated users to cause a denial of …
|
NVD-CWE-noinfo
|
CVE-2009-5061
|
2024-11-21 10:11 |
2011-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311828
|
3.5 |
LOW
|
ibm
|
lotus_quickr
|
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.11 services for Lotus Domino might allow remote authenticated users to cause a denial of service (daemon crash) by accessing an entry in…
|
NVD-CWE-noinfo
|
CVE-2009-5060
|
2024-11-21 10:11 |
2011-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311829
|
3.5 |
LOW
|
ibm
|
lotus_quickr
|
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.10 services for Lotus Domino might allow remote authenticated users to cause a denial of service (daemon crash) by checking out a docume…
|
NVD-CWE-noinfo
|
CVE-2009-5059
|
2024-11-21 10:11 |
2011-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311830
|
3.5 |
LOW
|
ibm
|
lotus_quickr
|
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.5 services for Lotus Domino allows remote authenticated users to cause a denial of service (daemon crash) by deleting an item that is ac…
|
NVD-CWE-noinfo
|
CVE-2009-5058
|
2024-11-21 10:11 |
2011-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311831
|
5.0 |
MEDIUM
|
otrs
|
otrs
|
The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to dec…
|
CWE-310
Cryptographic Issues
|
CVE-2009-5057
|
2024-11-21 10:11 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311832
|
2.1 |
LOW
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrict…
|
CWE-20
Improper Input Validation
|
CVE-2009-5056
|
2024-11-21 10:11 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311833
|
3.5 |
LOW
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5055
|
2024-11-21 10:11 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311834
|
7.5 |
HIGH
|
smarty
|
smarty
|
Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operatio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5054
|
2024-11-21 10:11 |
2011-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311835
|
7.5 |
HIGH
|
smarty
|
smarty
|
Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file.
|
NVD-CWE-noinfo
|
CVE-2009-5053
|
2024-11-21 10:11 |
2011-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311836
|
10.0 |
HIGH
|
smarty
|
smarty
|
Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-5052
|
2024-11-21 10:11 |
2011-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311837
|
9.3 |
HIGH
|
symantec
|
antivirus system_center antivirus_central_quarantine_server
|
HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x b…
|
CWE-20
Improper Input Validation
|
CVE-2010-0111
|
2024-11-21 10:11 |
2011-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311838
|
7.9 |
HIGH
|
symantec
|
antivirus system_center antivirus_central_quarantine_server
|
Multiple stack-based buffer overflows in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 1…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0110
|
2024-11-21 10:11 |
2011-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311839
|
5.0 |
MEDIUM
|
hastymail
|
hastymail2
|
Hastymail2 before RC 8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission with…
|
CWE-16
Configuration
|
CVE-2009-5051
|
2024-11-21 10:11 |
2011-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311840
|
7.5 |
HIGH
|
symantec
|
web_gateway
|
SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME paramete…
|
CWE-89
SQL Injection
|
CVE-2010-0115
|
2024-11-21 10:11 |
2011-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311841
|
6.8 |
MEDIUM
|
catb
|
gif2png
|
Stack-based buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to execute arbitrary code via a long command-line argument, as demonstrated by a CGI prog…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-5018
|
2024-11-21 10:11 |
2011-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311842
|
5.0 |
MEDIUM
|
polyvision
|
roomwizard_firmware roomwizard
|
The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which al…
|
CWE-200
Information Exposure
|
CVE-2010-0214
|
2024-11-21 10:11 |
2011-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311843
|
6.0 |
MEDIUM
|
activecollab
|
activecollab
|
ActiveCollab before 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to an object, via a crafted URL.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0215
|
2024-11-21 10:11 |
2011-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311844
|
6.8 |
MEDIUM
|
cisco
|
ios
|
CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the me…
|
CWE-399
Resource Management Errors
|
CVE-2009-5040
|
2024-11-21 10:11 |
2011-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311845
|
5.0 |
MEDIUM
|
cisco
|
ios
|
Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large n…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2009-5039
|
2024-11-21 10:11 |
2011-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311846
|
7.8 |
HIGH
|
cisco
|
ios
|
Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after an initial reload, which allows remote attackers to cause a denial of service (device reload) via a…
|
CWE-20
Improper Input Validation
|
CVE-2009-5038
|
2024-11-21 10:11 |
2011-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311847
|
5.0 |
MEDIUM
|
cisco
|
adaptive_security_appliance_software 5500_series_adaptive_security_appliance asa_5500
|
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allow remote attackers to cause a denial of service (ASDM syslog outage) via a long URL, aka Bug IDs CSCsm1126…
|
CWE-399
Resource Management Errors
|
CVE-2009-5037
|
2024-11-21 10:11 |
2011-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311848
|
2.6 |
LOW
|
apple
|
airport_express_base_station_firmware airport_extreme_base_station_firmware airport_express airport_extreme time_capsule
|
The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0039
|
2024-11-21 10:11 |
2010-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311849
|
7.5 |
HIGH
|
symantec
|
endpoint_protection
|
fw_charts.php in the reporting module in the Manager (aka SEPM) component in Symantec Endpoint Protection (SEP) 11.x before 11 RU6 MP2 allows remote attackers to bypass intended restrictions on repor…
|
CWE-20
Improper Input Validation
|
CVE-2010-0114
|
2024-11-21 10:11 |
2010-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311850
|
4.0 |
MEDIUM
|
ibm
|
lotus_notes_traveler
|
traveler.exe in IBM Lotus Notes Traveler before 8.0.1.3 CF1 allows remote authenticated users to cause a denial of service (daemon crash) via a malformed invitation document in a sync operation.
|
NVD-CWE-Other
|
CVE-2009-5036
|
2024-11-21 10:11 |
2010-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|