264801
|
- |
|
cisco
|
anyconnect_secure_mobility_client
|
The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain pri…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-2041
|
2011-09-7 12:16 |
2011-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264802
|
- |
|
adobe
|
blazeds livecycle_data_services livecycle
|
Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX…
|
CWE-20
Improper Input Validation
|
CVE-2011-2092
|
2011-09-7 12:16 |
2011-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264803
|
- |
|
balbir_singh
|
libcgroup
|
The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages or…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-1022
|
2011-09-7 12:15 |
2011-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264804
|
- |
|
proftpd
|
proftpd
|
Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH mess…
|
CWE-189
Numeric Errors
|
CVE-2011-1137
|
2011-09-7 12:15 |
2011-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264805
|
- |
|
exim
|
exim
|
The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or acc…
|
CWE-20
Improper Input Validation
|
CVE-2011-1407
|
2011-09-7 12:15 |
2011-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264806
|
- |
|
mediawiki
|
mediawiki
|
api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive informati…
|
CWE-200
Information Exposure
|
CVE-2010-2787
|
2011-09-7 12:10 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264807
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in profileinfo.php in MediaWiki before 1.15.5, when wgEnableProfileInfo is enabled, allows remote attackers to inject arbitrary web script or HTML via the fil…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2788
|
2011-09-7 12:10 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264808
|
- |
|
sixapart
|
movable_type
|
Multiple cross-site scripting (XSS) vulnerabilities in Six Apart Movable Type (MT) before 4.23 allow remote attackers to inject arbitrary web script or HTML via a (1) MTEntryAuthorUsername, (2) MTAut…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5845
|
2011-09-7 11:53 |
2009-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264809
|
- |
|
web-app.org
|
webapp
|
Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2007-1259
|
2011-09-1 13:00 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264810
|
- |
|
wordpress
|
wordpress
|
Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-20…
|
NVD-CWE-noinfo
|
CVE-2006-4028
|
2011-09-1 13:00 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|