266471
|
- |
|
fumitoshi_ukai
|
fml
|
mead.pl in fml 4.0.3 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/debugbuf temporary file.
|
CWE-59
Link Following
|
CVE-2008-4954
|
2009-08-26 14:17 |
2008-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266472
|
- |
|
dov_grobgeld
|
impose\+
|
impose in impose+ 0.2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*-tmp.ps and (2) /tmp/bboxx-* temporary files.
|
CWE-59
Link Following
|
CVE-2008-4960
|
2009-08-26 14:17 |
2008-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266473
|
- |
|
adobe
|
coldfusion
|
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2009-1878
|
2009-08-26 13:00 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266474
|
- |
|
buildbot
|
buildbot
|
Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2959
|
2009-08-26 02:30 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266475
|
- |
|
calimero.cms
|
calimero.cms
|
Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a calimero_webpage action.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0749
|
2009-08-25 14:09 |
2008-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266476
|
- |
|
ajsquare
|
free_polling_script
|
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. …
|
CWE-287
Improper Authentication
|
CVE-2008-7046
|
2009-08-24 19:30 |
2009-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266477
|
- |
|
wowraidmanager
|
wowraidmanager
|
The password_check function in auth/auth_phpbb3.php in WoW Raid Manager 3.5.1 before Patch 1, when using PHPBB3 authentication, (1) does not invoke the CheckPassword function with the required argume…
|
CWE-255
Credentials Management
|
CVE-2008-7050
|
2009-08-24 19:30 |
2009-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266478
|
- |
|
cisco
|
ios_xr
|
Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Att…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1154
|
2009-08-22 02:30 |
2009-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266479
|
- |
|
cisco
|
ios_xr
|
Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2056
|
2009-08-22 02:30 |
2009-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266480
|
- |
|
sun
|
virtual_desktop_infrastructure
|
Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow …
|
CWE-200
Information Exposure
|
CVE-2009-2856
|
2009-08-22 00:25 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|