264541
|
- |
|
novell
|
opensuse_build_service
|
The API in SUSE openSUSE Build Service (OBS) 2.0.x before 2.0.8 and 2.1.x before 2.1.6 allows attackers to bypass intended write-access restrictions and modify a (1) package or (2) project via unspec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-0466
|
2011-04-21 13:00 |
2011-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264542
|
- |
|
microsoft
|
windows_azure_sdk
|
Microsoft Windows Azure Software Development Kit (SDK) 1.3.x before 1.3.20121.1237, when Full IIS and a Web Role are used with an ASP.NET application, does not properly support the use of cookies for…
|
CWE-20
Improper Input Validation
|
CVE-2011-1068
|
2011-04-21 13:00 |
2011-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264543
|
- |
|
ibm
|
websphere_application_server
|
The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standar…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1307
|
2011-04-21 13:00 |
2011-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264544
|
- |
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registry or Federated Repository with RACF adapter is use…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1683
|
2011-04-21 13:00 |
2011-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264545
|
- |
|
lightneasy
|
lightneasy
|
Cross-site scripting (XSS) vulnerability in LightNEasy.php in LightNEasy 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, which is not properly handled in a …
|
CWE-79
Cross-site Scripting
|
CVE-2010-4753
|
2011-04-21 13:00 |
2011-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264546
|
- |
|
pwhois
|
layer_four_traceroute
|
Unspecified vulnerability in lft in pWhois Layer Four Traceroute (LFT) 3.x before 3.3 allows local users to gain privileges via a crafted command line.
|
NVD-CWE-noinfo
|
CVE-2011-0765
|
2011-04-21 11:33 |
2011-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264547
|
- |
|
hp
|
hp-ux
|
Unspecified vulnerability in the OS-Core.CORE2-KRN fileset in HP HP-UX B.11.23 and B.11.31 allows local users to cause a denial of service via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2011-0891
|
2011-04-21 11:33 |
2011-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264548
|
- |
|
cisco
|
ios
|
The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass authentication and have unspecified other impact by…
|
CWE-310
Cryptographic Issues
|
CVE-2011-0935
|
2011-04-21 11:33 |
2011-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264549
|
- |
|
cisco
|
ios
|
CVSS score derived from:
http://www.cisco.com/en/US/docs/ios/15_1s/release/notes/15_1s_caveats_15_1_2s.html
|
CWE-310
Cryptographic Issues
|
CVE-2011-0935
|
2011-04-21 11:33 |
2011-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264550
|
- |
|
gentoo
|
logrotate
|
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated…
|
CWE-20
Improper Input Validation
|
CVE-2011-1154
|
2011-04-21 11:33 |
2011-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|