266411
|
- |
|
claudio_matsuoka
|
extended_module_player
|
Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors relate…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-6732
|
2009-09-14 13:00 |
2009-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266412
|
- |
|
rivetcode
|
rivettracker
|
RivetTracker before 1.0 stores passwords in cleartext in config.php, which allows local users to discover passwords by reading config.php.
|
CWE-310
Cryptographic Issues
|
CVE-2008-7207
|
2009-09-12 01:30 |
2009-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266413
|
- |
|
marc_gloor
|
screenie
|
screenie in screenie 1.30.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.screenie.##### temporary file.
|
CWE-59
Link Following
|
CVE-2008-5371
|
2009-09-11 14:29 |
2008-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266414
|
- |
|
cmus
|
cmus
|
cmus-status-display in cmus 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cmus-status temporary file.
|
CWE-59
Link Following
|
CVE-2008-5375
|
2009-09-11 14:29 |
2008-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266415
|
- |
|
multi-website
|
multi_website
|
Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3162
|
2009-09-11 13:00 |
2009-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266416
|
- |
|
openwebmail.acatysmoof
|
openwebmail
|
Multiple cross-site scripting (XSS) vulnerabilities in OpenWebMail before 2.53 (Stable) allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-7202
|
2009-09-11 13:00 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266417
|
- |
|
allenthusiast
|
reviewpost_php_pro
|
Cross-site scripting (XSS) vulnerability in showproduct.php in ReviewPost Pro vB3 allows remote attackers to inject arbitrary web script or HTML via the date parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3147
|
2009-09-11 03:30 |
2009-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266418
|
- |
|
mark_reinsfelder
|
metashell
|
Unspecified vulnerability in metashell before 0.03 has unknown impact and attack vectors related to a "PATH execution security flaw," possibly an untrusted search path vulnerability.
|
NVD-CWE-noinfo
|
CVE-2008-7196
|
2009-09-10 19:30 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266419
|
- |
|
g15tools
|
g15daemon
|
Multiple unspecified vulnerabilities in G15Daemon before 1.9.4 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-7197
|
2009-09-10 19:30 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266420
|
- |
|
alecwh
|
phpns
|
Multiple unspecified vulnerabilities in phpns before 2.1.1beta1 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-7198
|
2009-09-10 19:30 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|