266421
|
- |
|
mhproducts
|
ero_auktion
|
SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-0723.
|
CWE-89
SQL Injection
|
CVE-2010-4614
|
2010-12-30 14:00 |
2010-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266422
|
- |
|
algisinfo
|
aicontactsafe
|
Cross-site scripting (XSS) vulnerability in the Algis Info aiContactSafe component before 2.0.14 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-4618
|
2010-12-30 14:00 |
2010-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266423
|
- |
|
realnetworks
|
helix_mobile_server helix_server helix_server_mobile
|
Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers …
|
CWE-189
Numeric Errors
|
CVE-2010-1319
|
2010-12-29 14:00 |
2010-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266424
|
- |
|
innovationdp
|
fdr\/upstrean
|
INNOVATION Data Processing FDR/UPSTREAM 3.3.0 (GA Oct 2003) allows remote attackers to cause a denial of service (service outage) via a sequence of TCP SYN packets to many ports, as demonstrated usin…
|
NVD-CWE-Other
|
CVE-2006-6404
|
2010-12-29 14:00 |
2009-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266425
|
- |
|
sentex
|
jhead
|
jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
|
CWE-59 NVD-CWE-noinfo
Link Following
|
CVE-2008-4639
|
2010-12-28 14:00 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266426
|
- |
|
mailscanner
|
mailscanner
|
mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) cla…
|
CWE-59
Link Following
|
CVE-2008-5312
|
2010-12-28 14:00 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266427
|
- |
|
mailscanner
|
mailscanner
|
mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clam…
|
CWE-59
Link Following
|
CVE-2008-5313
|
2010-12-28 14:00 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266428
|
- |
|
ibm
|
lotus_mobile_connect
|
Cross-site scripting (XSS) vulnerability in HTTP Access Services (HTTP-AS) in the Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4 allows remote attackers to inject arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4590
|
2010-12-28 03:55 |
2010-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266429
|
- |
|
ibm
|
lotus_mobile_connect
|
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly process TCP connection requests, which allows remote attackers to ca…
|
CWE-399
Resource Management Errors
|
CVE-2010-4594
|
2010-12-28 03:54 |
2010-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266430
|
- |
|
ibm
|
lotus_mobile_connect
|
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4595
|
2010-12-28 03:53 |
2010-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|