266921
|
- |
|
arrl
|
tqsllib
|
The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allow…
|
CWE-287
Improper Authentication
|
CVE-2009-0124
|
2009-02-6 16:05 |
2009-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266922
|
- |
|
punbb
|
punbb
|
Cross-site scripting (XSS) vulnerability in login.php in PunBB 1.3 and 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the password field.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5433
|
2009-02-6 16:03 |
2008-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266923
|
- |
|
freeradius
|
freeradius
|
freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4)…
|
CWE-59
Link Following
|
CVE-2008-4474
|
2009-02-6 16:00 |
2008-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266924
|
- |
|
sun
|
opensolaris
|
The UFS implementation in the kernel in Sun OpenSolaris snv_29 through snv_90 allows local users to cause a denial of service (panic) via the single posix_fallocate test in the SUSv3 POSIX test suite…
|
NVD-CWE-noinfo
|
CVE-2009-0131
|
2009-02-5 15:53 |
2009-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266925
|
- |
|
research_in_motion_limited
|
blackberry_enterprise_server blackberry_professional_software blackberry_unite
|
The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.…
|
CWE-399
Resource Management Errors
|
CVE-2009-0219
|
2009-02-5 15:53 |
2009-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266926
|
- |
|
gnome
|
nautilus-python
|
Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in the current working d…
|
NVD-CWE-Other
|
CVE-2009-0317
|
2009-02-5 15:53 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266927
|
- |
|
asp-dev
|
xm_events_diary
|
SQL injection vulnerability in diary_viewC.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information is…
|
CWE-89
SQL Injection
|
CVE-2008-5924
|
2009-02-5 15:52 |
2009-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266928
|
- |
|
torrenttrader
|
torrenttrader
|
TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (…
|
NVD-CWE-Other
|
CVE-2007-4536
|
2009-02-5 15:29 |
2007-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266929
|
- |
|
keep_toolkit
|
keep_toolkit
|
SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password.
|
CWE-89
SQL Injection
|
CVE-2009-0287
|
2009-02-5 14:00 |
2009-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266930
|
- |
|
codefixer
|
linkspro
|
SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirection parameter.
|
CWE-89
SQL Injection
|
CVE-2009-0431
|
2009-02-5 14:00 |
2009-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|