270041
|
- |
|
xfig
|
xfig
|
Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier allows remote attackers to cause a denial of service (application crash) via a long string in a malformed .fig file that uses t…
|
CWE-399
Resource Management Errors
|
CVE-2009-4228
|
2011-01-20 15:37 |
2009-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270042
|
- |
|
io-socket-ssl
|
io-socket-ssl
|
The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which all…
|
CWE-310
Cryptographic Issues
|
CVE-2009-3024
|
2011-01-20 15:35 |
2009-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270043
|
- |
|
wordpress
|
wordpress
|
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0682
|
2011-01-19 15:55 |
2010-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270044
|
- |
|
phpf1
|
max\'s_image_uploader
|
Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, a…
|
NVD-CWE-Other
|
CVE-2010-0390
|
2011-01-12 14:00 |
2010-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270045
|
- |
|
phpf1
|
max\'s_image_uploader
|
Per: http://cwe.mitre.org/data/definitions/434.html
'CWE-434: Unrestricted Upload of File with Dangerous Type'
|
NVD-CWE-Other
|
CVE-2010-0390
|
2011-01-12 14:00 |
2010-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270046
|
- |
|
embarcadero
|
interbase_smp_2009
|
Multiple stack-based buffer overflows in Embarcadero Technologies InterBase SMP 2009 9.0.3.437 allow remote attackers to execute arbitrary code via unknown vectors involving crafted packets. NOTE: t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0391
|
2011-01-12 14:00 |
2010-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270047
|
- |
|
provider4u
|
vsftpd_webmin_module
|
Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues."
|
NVD-CWE-noinfo
|
CVE-2009-4457
|
2011-01-11 15:38 |
2009-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270048
|
- |
|
cisco
|
unified_meetingplace
|
Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in …
|
CWE-89
SQL Injection
|
CVE-2010-0139
|
2011-01-7 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270049
|
- |
|
cisco
|
unified_meetingplace
|
MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified other data from the user database via a modified auth…
|
CWE-255
Credentials Management
|
CVE-2010-0141
|
2011-01-7 14:00 |
2010-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270050
|
- |
|
xerox
|
workcentre_6400_net_controller workcentre_6400_system_software
|
Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allow…
|
CWE-200
Information Exposure
|
CVE-2010-0549
|
2011-01-6 14:00 |
2010-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|