264241
|
- |
|
ibm
|
websphere_application_server
|
The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standar…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1307
|
2011-04-21 13:00 |
2011-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264242
|
- |
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registry or Federated Repository with RACF adapter is use…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1683
|
2011-04-21 13:00 |
2011-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264243
|
- |
|
lightneasy
|
lightneasy
|
Cross-site scripting (XSS) vulnerability in LightNEasy.php in LightNEasy 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, which is not properly handled in a …
|
CWE-79
Cross-site Scripting
|
CVE-2010-4753
|
2011-04-21 13:00 |
2011-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264244
|
- |
|
pwhois
|
layer_four_traceroute
|
Unspecified vulnerability in lft in pWhois Layer Four Traceroute (LFT) 3.x before 3.3 allows local users to gain privileges via a crafted command line.
|
NVD-CWE-noinfo
|
CVE-2011-0765
|
2011-04-21 11:33 |
2011-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264245
|
- |
|
hp
|
hp-ux
|
Unspecified vulnerability in the OS-Core.CORE2-KRN fileset in HP HP-UX B.11.23 and B.11.31 allows local users to cause a denial of service via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2011-0891
|
2011-04-21 11:33 |
2011-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264246
|
- |
|
cisco
|
ios
|
The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass authentication and have unspecified other impact by…
|
CWE-310
Cryptographic Issues
|
CVE-2011-0935
|
2011-04-21 11:33 |
2011-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264247
|
- |
|
cisco
|
ios
|
CVSS score derived from:
http://www.cisco.com/en/US/docs/ios/15_1s/release/notes/15_1s_caveats_15_1_2s.html
|
CWE-310
Cryptographic Issues
|
CVE-2011-0935
|
2011-04-21 11:33 |
2011-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264248
|
- |
|
gentoo
|
logrotate
|
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated…
|
CWE-20
Improper Input Validation
|
CVE-2011-1154
|
2011-04-21 11:33 |
2011-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264249
|
- |
|
gentoo
|
logrotate
|
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash…
|
CWE-399
Resource Management Errors
|
CVE-2011-1155
|
2011-04-21 11:33 |
2011-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264250
|
- |
|
gentoo
|
logrotate
|
The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1548
|
2011-04-21 11:33 |
2011-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|