270651
|
- |
|
zabbix
|
zabbix
|
The process_trap function in trapper/trapper.c in Zabbix Server before 1.6.6 allows remote attackers to cause a denial of service (crash) via a crafted request with data that lacks an expected : (col…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-4500
|
2010-01-12 14:00 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270652
|
- |
|
sun
|
java_system_web_server
|
Unspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process memory address and crafted data to TCP port 80, as…
|
NVD-CWE-noinfo
|
CVE-2010-0273
|
2010-01-11 22:37 |
2010-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270653
|
- |
|
adobe
|
illustrator
|
Buffer overflow in Adobe Illustrator CS3 13.0.3 and earlier and Illustrator CS4 14.0.0 allows attackers to execute arbitrary code via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-3952
|
2010-01-11 21:25 |
2010-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270654
|
- |
|
astha_bhatnagar
|
shindigintegrator
|
Cross-site scripting (XSS) vulnerability in the OpenSocial Shindig-Integrator module 5.x and 6.x before 6.x-2.1, a module for Drupal, allows remote authenticated users, with "create application" priv…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4514
|
2010-01-11 14:00 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270655
|
- |
|
speedtech
|
storm
|
The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4515
|
2010-01-9 05:29 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270656
|
- |
|
nanwich
|
faq_ask
|
Cross-site request forgery (CSRF) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requ…
|
CWE-352
Origin Validation Error
|
CVE-2009-4517
|
2010-01-9 02:50 |
2010-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270657
|
- |
|
verbatim
|
corporate_secure
|
Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proxima…
|
CWE-310
Cryptographic Issues
|
CVE-2010-0228
|
2010-01-8 14:00 |
2010-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270658
|
- |
|
verbatim
|
corporate_secure
|
Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents…
|
CWE-255
Credentials Management
|
CVE-2010-0229
|
2010-01-8 14:00 |
2010-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270659
|
- |
|
typo3
|
xds_staff
|
SQL injection vulnerability in the XDS Staff List (xds_staff) extension 0.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2009-4392
|
2010-01-8 14:00 |
2009-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270660
|
- |
|
malcom_box
|
lxr_cross_referencer
|
Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or HTML via the i parameter to the ident program.
|
CWE-79
Cross-site Scripting
|
CVE-2009-4497
|
2010-01-8 14:00 |
2010-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|