|
311851
|
8.1 |
HIGH
Network
|
gs-gpl_project
|
gs-gpl
|
I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.
|
CWE-362
Race Condition
|
CVE-2005-2352
|
2024-11-21 08:59 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311852
|
5.5 |
MEDIUM
Local
|
mutt debian
|
mutt debian_linux
|
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2005-2351
|
2024-11-21 08:59 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311853
|
6.1 |
MEDIUM
Network
|
websieve_project
|
websieve
|
Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.
|
CWE-79
Cross-site Scripting
|
CVE-2005-2350
|
2024-11-21 08:59 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311854
|
7.5 |
HIGH
Network
|
zoo_project
|
zoo
|
Zoo 2.10 has Directory traversal
|
CWE-22
Path Traversal
|
CVE-2005-2349
|
2024-11-21 08:59 |
2019-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311855
|
9.8 |
CRITICAL
Network
|
wp-plugins
|
secure_files
|
A vulnerability, which was classified as critical, was found in almosteffortless secure-files Plugin up to 1.1 on WordPress. Affected is the function sf_downloads of the file secure-files.php. The ma…
|
-
|
CVE-2005-10002
|
2024-11-21 08:56 |
2023-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311856
|
6.1 |
MEDIUM
Network
|
broadcom
|
symantec_siteminder
|
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The man…
|
CWE-601
Open Redirect
|
CVE-2005-10001
|
2024-11-21 08:56 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311857
|
9.8 |
CRITICAL
Network
|
goscript_project
|
goscript
|
go.cgi in GoScript 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) query string or (2) artarchive parameter.
|
NVD-CWE-Other
|
CVE-2004-2776
|
2024-11-21 08:54 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311858
|
7.5 |
HIGH
Network
|
underbit
|
libid3tag
|
id3_utf16_deserialize() in utf16.c in libid3tag through 0.15.1b misparses ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an endless loop allocating memory until an OOM condition…
|
CWE-399
Resource Management Errors
|
CVE-2004-2779
|
2024-11-21 08:54 |
2018-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311859
|
7.1 |
HIGH
Local
|
gentoo
|
portage
|
Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to restricted directories or execute restricted comm…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-2778
|
2024-11-21 08:54 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311860
|
10.0 |
HIGH
|
gehealthcare
|
centricity_image_vault_firmware
|
GE Healthcare Centricity Image Vault 3.x has a password of (1) gemnet for the administrator account, (2) webadmin for the webadmin administrator account of the ASACA DVD library, (3) an empty value f…
|
CWE-255
Credentials Management
|
CVE-2004-2777
|
2024-11-21 08:54 |
2015-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311861
|
7.5 |
HIGH
|
oracle redhat bsd_mailx_project heirloom
|
linux enterprise_linux bsd_mailx mailx
|
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
|
CWE-20
Improper Input Validation
|
CVE-2004-2771
|
2024-11-21 08:54 |
2014-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311862
|
4.0 |
MEDIUM
|
cerberusftp
|
ftp_server
|
Cerberus FTP Server before 4.0.3.0 allows remote authenticated users to list hidden files, even when the "Display hidden files" option is enabled, via the (1) MLSD or (2) MLST commands.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-2769
|
2024-11-21 08:54 |
2010-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311863
|
6.8 |
MEDIUM
|
tsugio_okamoto
|
lha
|
Buffer overflow in LHA 1.14 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to "command line processing," a di…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2004-0694
|
2024-11-21 08:49 |
2011-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311864
|
6.1 |
MEDIUM
Network
|
ibm
|
iss_blackice_pc_protection
|
A vulnerability was found in ISS BlackICE PC Protection. It has been rated as problematic. Affected by this issue is the Update Handler. The manipulation with an unknown input leads to cross site scr…
|
CWE-79
Cross-site Scripting
|
CVE-2003-5003
|
2024-11-21 08:47 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311865
|
5.3 |
MEDIUM
Network
|
ibm
|
iss_blackice_pc_protection
|
A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update Handler which allows cleartext transmission of dat…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2003-5002
|
2024-11-21 08:47 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311866
|
9.8 |
CRITICAL
Network
|
ibm
|
iss_blackice_pc_protection
|
A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Detection. The manipulation as part of POST/PUT/DELETE…
|
NVD-CWE-noinfo
|
CVE-2003-5001
|
2024-11-21 08:47 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311867
|
7.5 |
HIGH
Network
|
haxx
|
curl
|
curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.
|
CWE-255
Credentials Management
|
CVE-2003-1605
|
2024-11-21 08:47 |
2018-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311868
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending …
|
NVD-CWE-Other
|
CVE-2003-1604
|
2024-11-21 08:47 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311869
|
10.0 |
HIGH
|
gehealthcare
|
discovery_vh
|
GE Healthcare Discovery VH has a default password of (1) interfile for the ftpclient user of the Interfile server or (2) "2" for the LOCAL user of the FTP server for the Codonics printer, which has u…
|
CWE-255
Credentials Management
|
CVE-2003-1603
|
2024-11-21 08:47 |
2015-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311870
|
7.5 |
HIGH
|
wordpress
|
wordpress
|
PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.
|
CWE-94
Code Injection
|
CVE-2003-1599
|
2024-11-21 08:47 |
2014-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311871
|
7.5 |
HIGH
|
wordpress
|
wordpress
|
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.
|
CWE-89
SQL Injection
|
CVE-2003-1598
|
2024-11-21 08:47 |
2014-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311872
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.
|
-
|
CVE-2002-2438
|
2024-11-21 08:43 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311873
|
9.8 |
CRITICAL
Network
|
snoopy_project
|
snoopy
|
Snoopy before 2.0.0 has a security hole in exec cURL
|
CWE-20
Improper Input Validation
|
CVE-2002-2444
|
2024-11-21 08:43 |
2019-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311874
|
7.8 |
HIGH
Local
|
gnu
|
gcc
|
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2002-2439
|
2024-11-21 08:43 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311875
|
10.0 |
HIGH
|
gehealthcare
|
millennium_mg_firmware millennium_nc_firmware millennium_myosight_firmware
|
GE Healthcare Millennium MG, NC, and MyoSIGHT has a password of insite.genieacq for the insite account that cannot be changed without disabling product functionality for remote InSite support, which …
|
CWE-255
Credentials Management
|
CVE-2002-2446
|
2024-11-21 08:43 |
2015-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311876
|
10.0 |
HIGH
|
gehealthcare
|
millennium_myosight millennium_nc millennium_mg
|
GE Healthcare Millennium MG, NC, and MyoSIGHT has a default password of (1) root.genie for the root user, (2) "service." for the service user, (3) admin.genie for the admin user, (4) reboot for the r…
|
NVD-CWE-noinfo
|
CVE-2002-2445
|
2024-11-21 08:43 |
2015-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311877
|
5.0 |
MEDIUM
|
mit opensuse fedoraproject redhat debian canonical
|
kerberos_5 opensuse fedora enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_desktop enterprise_linux_eus debian_linux ubunt…
|
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial o…
|
CWE-20
Improper Input Validation
|
CVE-2002-2443
|
2024-11-21 08:43 |
2013-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311878
|
5.0 |
MEDIUM
|
mozilla
|
firefox thunderbird seamonkey
|
The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getC…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2437
|
2024-11-21 08:43 |
2011-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311879
|
4.3 |
MEDIUM
|
mozilla
|
firefox thunderbird seamonkey
|
The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote…
|
CWE-200
Information Exposure
|
CVE-2002-2436
|
2024-11-21 08:43 |
2011-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311880
|
4.3 |
MEDIUM
|
microsoft
|
internet_explorer ie
|
The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive in…
|
CWE-200
Information Exposure
|
CVE-2002-2435
|
2024-11-21 08:43 |
2011-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311881
|
7.5 |
HIGH
Network
|
balasys siemens suse f5 hpe stormshield
|
dheater scalance_w1750d_firmware linux_enterprise_server big-iq_centralized_management traffix_signaling_delivery_controller big-ip_service_proxy big-ip_access_policy_manager big…
|
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exp…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2002-20001
|
2024-11-21 08:42 |
2021-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311882
|
10.0 |
HIGH
|
gehealthcare
|
entegra_p\&r
|
GE Healthcare eNTEGRA P&R has a password of (1) entegra for the entegra user, (2) passme for the super user of the Polestar/Polestar-i Starlink 4 upgrade, (3) 0 for the entegra user of the Codonics p…
|
CWE-255
Credentials Management
|
CVE-2001-1594
|
2024-11-21 08:38 |
2015-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311883
|
2.1 |
LOW
|
gnu
|
a2ps
|
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink atta…
|
CWE-59
Link Following
|
CVE-2001-1593
|
2024-11-21 08:38 |
2014-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311884
|
7.5 |
HIGH
Network
|
openssl
|
openssl
|
crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryptographic protection…
|
CWE-310
Cryptographic Issues
|
CVE-2000-1254
|
2024-11-21 08:34 |
2016-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311885
|
2.1 |
LOW
|
apache
|
jserv
|
The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensiti…
|
CWE-16
Configuration
|
CVE-2000-1247
|
2024-11-21 08:34 |
2011-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311886
|
9.8 |
CRITICAL
Network
|
gnu
|
glibc
|
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dan…
|
CWE-252
Unchecked Return Value
|
CVE-1999-0199
|
2024-11-21 08:28 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311887
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
x86/tdx: Fix data leak in mmio_read()
The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an
address from the VMM…
|
NVD-CWE-noinfo
|
CVE-2024-46794
|
2024-11-21 05:56 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311888
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Skip inactive planes within ModeSupportAndSystemConfiguration
[Why]
Coverity reports Memory - illegal accesses.
…
|
NVD-CWE-noinfo
|
CVE-2024-46812
|
2024-11-21 05:48 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311889
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix firmware crash due to invalid peer nss
Currently, if the access point receives an association
request containin…
|
NVD-CWE-noinfo
|
CVE-2024-46827
|
2024-11-21 05:40 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311890
|
- |
-
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected i…
|
-
|
CVE-2024-52762
|
2024-11-21 05:35 |
2024-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311891
|
- |
-
|
-
|
-
|
In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional executio…
|
-
|
CVE-2018-9409
|
2024-11-21 05:35 |
2024-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311892
|
9.8 |
CRITICAL
Network
|
tenda
|
ac6_firmware
|
Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-52714
|
2024-11-21 05:35 |
2024-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311893
|
7.5 |
HIGH
Network
|
qualcomm
|
315_5g_iot_modem_firmware apq8064au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware ar9380_firmware csr8811_firmware csra6620_firmware csra6640_firmware csrb31024…
|
Transient DOS while parsing ESP IE from beacon/probe response frame.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33014
|
2024-11-21 05:35 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311894
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
io_uring: check if we need to reschedule during overflow flush
In terms of normal application usage, this list will always be emp…
|
NVD-CWE-noinfo
|
CVE-2024-50060
|
2024-11-21 05:25 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311895
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: Fix ERR_PTR dereference in uvc_v4l2.c
Fix potential dereferencing of ERR_PTR() in find_format_by_pix()
and uvc_…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50056
|
2024-11-21 05:18 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311896
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ntfs3: Change to non-blocking allocation in ntfs_d_hash
d_hash is done while under "rcu-walk" and should not sleep.
__get_name() …
|
NVD-CWE-noinfo
|
CVE-2024-50065
|
2024-11-21 05:07 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311897
|
7.5 |
HIGH
Network
|
qualcomm
|
ar8035_firmware csr8811_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_platform_firmware immersive…
|
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33015
|
2024-11-21 04:57 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311898
|
7.5 |
HIGH
Network
|
qualcomm
|
csr8811_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_platform_firmware immersive_home_214_platform_firmware immersive_home_21…
|
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33025
|
2024-11-21 04:53 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311899
|
7.5 |
HIGH
Network
|
qualcomm
|
ar8035_firmware csr8811_firmware fastconnect_6700_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_platform_firmware immersive…
|
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-33024
|
2024-11-21 04:42 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311900
|
7.5 |
HIGH
Network
|
qualcomm
|
ar8035_firmware csr8811_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware immersive_home_214_platform_firmware immersive_home_216_platform_firmw…
|
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33018
|
2024-11-21 04:40 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|