|
345801
|
5.0 |
MEDIUM
|
novell
|
edirectory
|
Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue …
|
NVD-CWE-noinfo
|
CVE-2010-0666
|
2010-02-22 14:00 |
2010-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345802
|
9.0 |
HIGH
|
accellion
|
secure_file_transfer_appliance
|
Static code injection vulnerability in the administrative web interface in Accellion Secure File Transfer Appliance allows remote authenticated administrators to inject arbitrary shell commands by ap…
|
CWE-94
Code Injection
|
CVE-2009-4646
|
2010-02-22 14:00 |
2010-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345803
|
6.8 |
MEDIUM
|
k5n
|
webcalendar
|
Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via un…
|
CWE-352
Origin Validation Error
|
CVE-2010-0638
|
2010-02-16 14:00 |
2010-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345804
|
10.0 |
HIGH
|
juniper
|
odyssey_access_client
|
Stack-based buffer overflow in dsInstallerService.dll in the Juniper Installer Service, as used in Juniper Odyssey Access Client 4.72.11421.0 and other products, allows remote attackers to execute ar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4643
|
2010-02-16 14:00 |
2010-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345805
|
7.5 |
HIGH
|
eicrasoft
|
eicra_car_rental-script
|
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow remote attackers to execute arbitrary SQL commands via the (1) users (username…
|
CWE-89
SQL Injection
|
CVE-2010-0631
|
2010-02-15 14:00 |
2010-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345806
|
7.5 |
HIGH
|
will_estes
|
flex
|
Unspecified vulnerability in Fast Lexical Analyzer Generator (flex) before 2.5.35 has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2010-0634
|
2010-02-15 14:00 |
2010-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345807
|
7.5 |
HIGH
|
jevents
|
jevents_search_plugin
|
SQL injection vulnerability in the plgSearchEventsearch::onSearch method in eventsearch.php in the JEvents Search plugin 1.5 through 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL…
|
CWE-89
SQL Injection
|
CVE-2010-0635
|
2010-02-15 14:00 |
2010-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345808
|
10.0 |
HIGH
|
hp
|
operations_agent
|
HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-255
Credentials Management
|
CVE-2010-0444
|
2010-02-13 16:22 |
2010-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345809
|
7.5 |
HIGH
|
osticket
|
osticket
|
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.
|
CWE-89
SQL Injection
|
CVE-2010-0605
|
2010-02-12 14:00 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345810
|
7.5 |
HIGH
|
novaboard
|
novaboard
|
SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter in a search action.
|
CWE-89
SQL Injection
|
CVE-2010-0608
|
2010-02-12 14:00 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345811
|
4.9 |
MEDIUM
|
netbsd
|
netbsd
|
Integer signedness error in NetBSD 4.0, 5.0, and NetBSD-current before 2010-01-21 allows local users to cause a denial of service (kernel panic) via a negative mixer index number being passed to (1) …
|
CWE-189
Numeric Errors
|
CVE-2010-0561
|
2010-02-9 14:00 |
2010-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345812
|
4.3 |
MEDIUM
|
sun
|
one_web_server
|
Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP a…
|
CWE-189
Numeric Errors
|
CVE-2003-1579
|
2010-02-8 23:55 |
2010-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345813
|
7.5 |
HIGH
|
ibm
|
cognos_express
|
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.
|
CWE-255
Credentials Management
|
CVE-2010-0557
|
2010-02-8 14:00 |
2010-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345814
|
4.3 |
MEDIUM
|
apache
|
http_server
|
The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which al…
|
CWE-189
Numeric Errors
|
CVE-2003-1580
|
2010-02-8 14:00 |
2010-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345815
|
2.6 |
LOW
|
apache
|
http_server
|
The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafte…
|
CWE-79
Cross-site Scripting
|
CVE-2003-1581
|
2010-02-8 14:00 |
2010-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345816
|
5.0 |
MEDIUM
|
tor
|
tor
|
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymi…
|
CWE-200
Information Exposure
|
CVE-2010-0383
|
2010-02-5 16:13 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345817
|
5.0 |
MEDIUM
|
ircd-ratbox
|
ircd-ratbox
|
cache.c in ircd-ratbox before 2.2.9 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a HELP command.
|
NVD-CWE-Other
|
CVE-2010-0300
|
2010-02-5 14:00 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345818
|
5.0 |
MEDIUM
|
ircd-ratbox
|
ircd-ratbox
|
Per: http://cwe.mitre.org/data/definitions/476.html
'CWE-476: NULL Pointer Dereference'
|
NVD-CWE-Other
|
CVE-2010-0300
|
2010-02-5 14:00 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345819
|
5.0 |
MEDIUM
|
xerox
|
workcentre_5632 workcentre_5638 workcentre_5645 workcentre_5655 workcentre_5665 workcentre_5675 workcentre_5687
|
Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow remote attackers to (1) access mailboxes via unkno…
|
CWE-200
Information Exposure
|
CVE-2010-0548
|
2010-02-5 14:00 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345820
|
6.8 |
MEDIUM
|
ircd-hybrid ircd-ratbox oftc
|
ircd-hybrid ircd-ratbox oftc-hybrid
|
Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allo…
|
CWE-189
Numeric Errors
|
CVE-2009-4016
|
2010-02-5 14:00 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345821
|
4.3 |
MEDIUM
|
comtrend
|
ct-507it_adsl_router
|
Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-0470
|
2010-02-3 14:00 |
2010-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345822
|
7.5 |
HIGH
|
viewvc
|
viewvc
|
query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access r…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0005
|
2010-02-2 14:00 |
2010-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345823
|
5.0 |
MEDIUM
|
mozilla
|
seamonkey thunderbird
|
Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or APP_TYPE_EDITOR, which makes it easier for remote a…
|
CWE-200
Information Exposure
|
CVE-2009-4629
|
2010-02-2 14:00 |
2010-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345824
|
10.0 |
HIGH
|
cisco
|
unified_meetingplace
|
Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.3, and possibly 5 allow remote attackers to create (1) user or (2) a…
|
NVD-CWE-noinfo
|
CVE-2010-0140
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345825
|
10.0 |
HIGH
|
cisco
|
unified_meetingplace
|
Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml
Affected Products
Vulnerable Products
Cisco Unified MeetingPlace versions 5, 6, and 7 are each affec…
|
NVD-CWE-noinfo
|
CVE-2010-0140
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345826
|
8.5 |
HIGH
|
cisco
|
unified_meetingplace
|
MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote authenticated users to gain privileges via a modified authentication sequence, aka Bug ID CSCsv66530.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0142
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345827
|
8.5 |
HIGH
|
cisco
|
unified_meetingplace
|
Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml
Affected Products
Vulnerable Products
Cisco Unified MeetingPlace versions 5, 6, and 7 are each affec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0142
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345828
|
4.3 |
MEDIUM
|
sun
|
java_system_application_server
|
The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credential…
|
CWE-16
Configuration
|
CVE-2010-0386
|
2010-01-31 14:00 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345829
|
4.3 |
MEDIUM
|
sun
|
java_system_application_server
|
Per: http://sunsolve.sun.com/search/document.do?assetkey=1-66-200942-1
Contributing Factors
This issue can occur in the following releases:
* Sun Java System Application Server Standar…
|
CWE-16
Configuration
|
CVE-2010-0386
|
2010-01-31 14:00 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345830
|
5.0 |
MEDIUM
|
sun
|
java_system_web_server
|
The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request that lacks a method to…
|
NVD-CWE-Other
|
CVE-2010-0389
|
2010-01-31 14:00 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345831
|
5.0 |
MEDIUM
|
sun
|
java_system_web_server
|
Per: http://cwe.mitre.org/data/slices/2000.html
CWE-476 NULL Pointer Dereference
|
NVD-CWE-Other
|
CVE-2010-0389
|
2010-01-31 14:00 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345832
|
5.0 |
MEDIUM
|
mozilla
|
firefox seamonkey thunderbird
|
Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML documents, which makes it easier for remote attacke…
|
CWE-200
Information Exposure
|
CVE-2009-4630
|
2010-01-31 14:00 |
2010-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345833
|
7.5 |
HIGH
|
sun
|
storedge_6130_arrays
|
Unspecified vulnerability on certain Sun StorEdge 6130 (SE6130) Controller Arrays allows remote attackers to delete data via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2005-4885
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345834
|
7.5 |
HIGH
|
sun
|
storedge_6130_arrays
|
Per: http://sunsolve.sun.com/search/document.do?assetkey=1-66-200971-1
This issue can occur on the following platform:
* Sun StorEdge 6130 arrays with a serial number in the range of 0451AW…
|
NVD-CWE-noinfo
|
CVE-2005-4885
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345835
|
7.5 |
HIGH
|
sun
|
storedge_6130_arrays
|
Per: http://sunsolve.sun.com/search/document.do?assetkey=1-66-200971-1
"Resolution
Customers with an array that falls within the serial number range defined above should contact their Sun aut…
|
NVD-CWE-noinfo
|
CVE-2005-4885
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345836
|
4.3 |
MEDIUM
|
sun
|
iplanet_messaging_server one_messaging_server
|
Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to injec…
|
CWE-79
Cross-site Scripting
|
CVE-2004-2765
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345837
|
4.3 |
MEDIUM
|
sun
|
iplanet_messaging_server one_messaging_server
|
Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "…
|
CWE-200
Information Exposure
|
CVE-2004-2766
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345838
|
4.6 |
MEDIUM
|
symantec
|
vxfs
|
VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2003-1575
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345839
|
10.0 |
HIGH
|
sun
|
change_manager
|
Buffer overflow in pamverifier in Change Manager (CM) 1.0 for Sun Management Center (SunMC) 3.0 on Solaris 8 and 9 on the sparc platform allows remote attackers to execute arbitrary code via unspecif…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2003-1576
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345840
|
10.0 |
HIGH
|
sun
|
change_manager
|
Per: http://sunsolve.sun.com/search/document.do?assetkey=1-66-201231-1
* "SunMC Change Manager" 1.0 is an unbundled Sun Management Center (SunMC) 3.0 add-on. It is not a part of the SunMC …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2003-1576
|
2010-01-31 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345841
|
5.0 |
MEDIUM
|
tor
|
tor
|
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge des…
|
CWE-200
Information Exposure
|
CVE-2010-0385
|
2010-01-26 14:00 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345842
|
4.3 |
MEDIUM
|
ibm
|
lotus_domino_server
|
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authen…
|
CWE-16
Configuration
|
CVE-2008-7253
|
2010-01-26 14:00 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345843
|
6.8 |
MEDIUM
|
oracle
|
database_server
|
Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 10.1.0.4 (10g) allows remote authenticated attackers to affect availability via unknown vectors, aka DB02.
|
NVD-CWE-noinfo
|
CVE-2005-4884
|
2010-01-26 14:00 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345844
|
5.0 |
MEDIUM
|
jce-tech
|
php_calendars_script
|
install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application settings via a direct request. NOTE: this is only a …
|
CWE-16 CWE-264
Configuration Permissions, Privileges, and Access Controls
|
CVE-2010-0380
|
2010-01-25 14:00 |
2010-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345845
|
7.5 |
HIGH
|
phpmyspace
|
phpmyspace
|
SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a show_stats action…
|
CWE-89
SQL Injection
|
CVE-2010-0381
|
2010-01-25 14:00 |
2010-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345846
|
7.5 |
HIGH
|
phpmyspace
|
phpmyspace
|
SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a play_game action.…
|
CWE-89
SQL Injection
|
CVE-2010-0377
|
2010-01-23 03:30 |
2010-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345847
|
5.0 |
MEDIUM
|
sambar
|
sambar_server
|
search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.
|
NVD-CWE-Other
|
CVE-2000-0835
|
2010-01-16 14:00 |
2000-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345848
|
5.0 |
MEDIUM
|
webtrends
|
reporting_center
|
WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an…
|
CWE-200
Information Exposure
|
CVE-2002-0596
|
2010-01-16 14:00 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345849
|
6.4 |
MEDIUM
|
tftpd32
|
tftpd32
|
tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2353
|
2009-11-24 14:15 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345850
|
10.0 |
HIGH
|
jean-jacques_sarton
|
mtink
|
Buffer overflow in MTink in the printer-filters-utils package allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2005-4604
|
2009-11-12 14:51 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|