267031
|
- |
|
anything-digital
|
com_jcalpro
|
PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro or JCP) component 1.5.3.6 for Joomla! allows remote attackers to execute arbitra…
|
CWE-94
Code Injection
|
CVE-2009-4431
|
2010-06-29 13:00 |
2009-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267032
|
- |
|
ibm
|
db2
|
The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4438
|
2010-06-29 13:00 |
2009-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267033
|
- |
|
ibm
|
db2
|
Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (instance crash) by compilin…
|
NVD-CWE-noinfo
|
CVE-2009-4439
|
2010-06-29 13:00 |
2009-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267034
|
- |
|
headstart_solutions
|
deskpro
|
install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2006-6998
|
2010-06-29 13:00 |
2007-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267035
|
- |
|
mozilla
|
bugzilla
|
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configur…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-0180
|
2010-06-29 02:30 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267036
|
- |
|
mozilla
|
bugzilla
|
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL,…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-1204
|
2010-06-29 02:30 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267037
|
- |
|
maradns
|
maradns
|
parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of…
|
NVD-CWE-Other
|
CVE-2010-2444
|
2010-06-28 13:00 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267038
|
- |
|
maradns
|
maradns
|
Per: http://cwe.mitre.org/data/definitions/476.html
'NULL Pointer Dereference'
|
NVD-CWE-Other
|
CVE-2010-2444
|
2010-06-28 13:00 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267039
|
- |
|
jamroom
|
jamroom
|
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2463
|
2010-06-28 13:00 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267040
|
- |
|
linearcorp
|
emerge_50 emerge_5000
|
The Linear eMerge 50 and 5000 uses a default password of eMerge for the IEIeMerge account, which makes it easier for remote attackers to obtain Video Recorder data by establishing a session to the de…
|
CWE-255
Credentials Management
|
CVE-2010-2469
|
2010-06-28 13:00 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|