270941
|
- |
|
ibm
|
db2
|
The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact an…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4331
|
2010-10-7 14:44 |
2009-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270942
|
- |
|
ibm
|
db2
|
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which ha…
|
NVD-CWE-noinfo
|
CVE-2009-3471
|
2010-10-7 14:42 |
2009-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270943
|
- |
|
opera
|
opera_browser
|
Opera before 10.10 permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers…
|
CWE-200
Information Exposure
|
CVE-2010-0653
|
2010-09-21 14:46 |
2010-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270944
|
- |
|
fujitsu
|
e-pares
|
Session fixation vulnerability in Fujitsu e-Pares V01 L01, L03, L10, L20, L30 allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2010-2149
|
2010-09-21 13:00 |
2010-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270945
|
- |
|
linux
|
linux_kernel
|
umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen…
|
NVD-CWE-Other
|
CVE-2007-0822
|
2010-09-15 14:43 |
2007-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270946
|
- |
|
suse
|
suse_linux
|
Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-0460
|
2010-09-15 14:41 |
2007-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270947
|
- |
|
clam_anti-virus
|
clamav
|
Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.
|
NVD-CWE-Other
|
CVE-2006-5874
|
2010-09-15 14:30 |
2006-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270948
|
- |
|
php_group
|
php
|
Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption.
|
NVD-CWE-Other
|
CVE-2006-3018
|
2010-09-15 13:54 |
2006-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270949
|
- |
|
mono
|
mono
|
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as dem…
|
CWE-79
Cross-site Scripting
|
CVE-2010-1459
|
2010-09-9 14:41 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270950
|
- |
|
otrs
|
otrs
|
Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 …
|
CWE-89
SQL Injection
|
CVE-2010-0438
|
2010-09-9 14:39 |
2010-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|