270791
|
- |
|
sun
|
java_system_access_manager java_system_web_server
|
The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct cl…
|
NVD-CWE-noinfo
|
CVE-2009-2713
|
2009-08-15 14:23 |
2009-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270792
|
- |
|
freearcadescript
|
free_arcade_script
|
Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2771
|
2009-08-15 02:30 |
2009-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270793
|
- |
|
squid-cache
|
squid
|
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incom…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2621
|
2009-08-12 14:30 |
2009-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270794
|
- |
|
squid-cache
|
squid
|
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) miss…
|
CWE-20
Improper Input Validation
|
CVE-2009-2622
|
2009-08-12 14:30 |
2009-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270795
|
- |
|
znc
|
znc
|
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.
|
CWE-22
Path Traversal
|
CVE-2009-2658
|
2009-08-12 14:30 |
2009-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270796
|
- |
|
django_project
|
django
|
The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory trav…
|
CWE-22
Path Traversal
|
CVE-2009-2659
|
2009-08-12 14:30 |
2009-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270797
|
- |
|
ibm
|
aix
|
A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by le…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2669
|
2009-08-12 14:30 |
2009-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270798
|
- |
|
adobe
|
acrobat acrobat_reader
|
Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remot…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0888
|
2009-08-12 14:27 |
2009-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270799
|
- |
|
adobe
|
acrobat acrobat_reader
|
Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remot…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0889
|
2009-08-12 14:27 |
2009-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270800
|
- |
|
ibm
|
db2
|
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-20…
|
CWE-16
Configuration
|
CVE-2008-6820
|
2009-08-12 14:25 |
2009-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|