264951
|
- |
|
turbogears
|
turbogears2
|
The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication via a forged authoriz…
|
CWE-310
Cryptographic Issues
|
CVE-2009-5014
|
2010-11-9 14:00 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264952
|
- |
|
gnome
|
gnome-shell
|
gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working dire…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4000
|
2010-11-8 14:00 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264953
|
- |
|
hp
|
virtual_server_environment
|
Unspecified vulnerability in HP Virtual Server Environment before 6.2 allows remote attackers to read arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-3990
|
2010-11-6 14:39 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264954
|
- |
|
hp
|
hp version_control_repository_manager
|
Cross-site scripting (XSS) vulnerability in HP Version Control Repository Manager (VCRM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3994
|
2010-11-6 14:39 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264955
|
- |
|
cisco
|
ciscoworks_common_services ciscoworks_lan_management_solution qos_policy_manager security_manager telepresence_readiness_assessment_manager unified_operations_manager unified_servic…
|
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3036
|
2010-11-6 14:38 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264956
|
- |
|
vim
|
gvim
|
Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary co…
|
NVD-CWE-Other
|
CVE-2010-3914
|
2010-11-5 13:00 |
2010-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264957
|
- |
|
vim
|
gvim
|
http://www.kb.cert.org/vuls/id/707943
|
NVD-CWE-Other
|
CVE-2010-3914
|
2010-11-5 13:00 |
2010-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264958
|
- |
|
vim
|
gvim
|
Per: http://cwe.mitre.org/data/definitions/426.html
'CWE-426: Untrusted Search Path'
|
NVD-CWE-Other
|
CVE-2010-3914
|
2010-11-5 13:00 |
2010-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264959
|
- |
|
microsoft
|
windows_2003_server windows_7 windows_vista windows_xp
|
Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Busine…
|
NVD-CWE-Other
|
CVE-2010-4182
|
2010-11-5 13:00 |
2010-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264960
|
- |
|
sterlitetechnologies
|
sam300_ax_router
|
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote attackers to inject arbitrary web script or HTML via the Stat_Radio parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-0607
|
2010-11-4 13:00 |
2010-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|