270921
|
- |
|
edraw
|
pdf_viewer_component
|
Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows remote attackers to create and overwrite arbitrary…
|
CWE-94
Code Injection
|
CVE-2009-2169
|
2009-06-23 13:00 |
2009-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270922
|
- |
|
elvinbts
|
elvinbts
|
Cross-site scripting (XSS) vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the title (aka subject) field.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2126
|
2009-06-22 13:00 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270923
|
- |
|
elvinbts
|
elvinbts
|
SQL injection vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the title (aka subject) field.
|
CWE-89
SQL Injection
|
CVE-2009-2128
|
2009-06-22 13:00 |
2009-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270924
|
- |
|
pagedowntech
|
pdshoppro
|
Cross-site scripting (XSS) vulnerability in search.asp in PDshopPro, when downloaded before 20070308, allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2032
|
2009-06-20 14:29 |
2009-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270925
|
- |
|
apple
|
safari
|
Apple Safari before 4.0 does not properly check for revoked Extended Validation (EV) certificates, which makes it easier for remote attackers to trick a user into accepting an invalid certificate.
|
CWE-255
Credentials Management
|
CVE-2009-1682
|
2009-06-19 14:32 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270926
|
- |
|
apple
|
safari
|
CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript code by p…
|
CWE-94
Code Injection
|
CVE-2009-1704
|
2009-06-19 14:32 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270927
|
- |
|
apple
|
safari
|
The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstances upon (1) disabling of the feature or (2) exit o…
|
CWE-200
Information Exposure
|
CVE-2009-1706
|
2009-06-19 14:32 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270928
|
- |
|
apple
|
safari
|
Apple Safari before 4.0 does not prevent calls to the open-help-anchor URL handler by web sites, which allows remote attackers to open arbitrary local help files, and execute arbitrary code or obtain…
|
NVD-CWE-Other
|
CVE-2009-1708
|
2009-06-19 14:32 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270929
|
- |
|
apple
|
safari
|
CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-1716
|
2009-06-19 14:32 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270930
|
- |
|
sun
|
opensolaris
|
Unspecified vulnerability in idmap in Sun OpenSolaris snv_88 through snv_110, when a CIFS server is enabled, allows local users to cause a denial of service (idpmapd daemon crash and idmapd outage) v…
|
NVD-CWE-noinfo
|
CVE-2009-2012
|
2009-06-19 14:32 |
2009-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|