264321
|
- |
|
gallarific
|
gallarific
|
Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote attackers to edit objects via a direct request, d…
|
CWE-287
Improper Authentication
|
CVE-2008-1469
|
2011-07-25 13:00 |
2008-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264322
|
- |
|
gallarific
|
gallarific
|
More information available at: http://www.securityfocus.com/bid/28163/info
|
CWE-287
Improper Authentication
|
CVE-2008-1469
|
2011-07-25 13:00 |
2008-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264323
|
- |
|
linpha
|
linpha
|
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via (1) ftp/index.php, (2) viewer.php, (3) functions/other.php…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1487
|
2011-07-25 13:00 |
2008-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264324
|
- |
|
netbsd
|
netbsd
|
The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket consumption) via an…
|
CWE-20
Improper Input Validation
|
CVE-2006-6653
|
2011-07-25 13:00 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264325
|
- |
|
netbsd
|
netbsd
|
This vulnerability is addressed in the following product updates:
NetBSD, NetBSD, current (10/23/2006)
NetBSD, NetBSD, 3.0 (10/24/2006)
NetBSD, NetBSD, 3.0.1 (10/24/2006)
NetBSD, NetBSD, 2.0 (10…
|
CWE-20
Improper Input Validation
|
CVE-2006-6653
|
2011-07-25 13:00 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264326
|
- |
|
web-app.net
|
webapp
|
Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2006-6687
|
2011-07-25 13:00 |
2006-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264327
|
- |
|
apple
|
iphone_os
|
The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site. NOTE…
|
CWE-200
Information Exposure
|
CVE-2011-0195
|
2011-07-23 11:39 |
2011-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264328
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CF…
|
CWE-189
Numeric Errors
|
CVE-2011-0201
|
2011-07-23 11:39 |
2011-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264329
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font …
|
CWE-189
Numeric Errors
|
CVE-2011-0202
|
2011-07-23 11:39 |
2011-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264330
|
- |
|
apple
|
cfnetwork safari
|
CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via…
|
CWE-310
Cryptographic Issues
|
CVE-2011-0214
|
2011-07-22 13:00 |
2011-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|